Request / Response
Request
GET Parameters
| Key | Value |
|---|---|
| cmd | "cat /root/.aws/credentials|echo TEST_RCE_2025" |
POST Parameters
No POST parameters
Uploaded Files
No files were uploaded
Request Attributes
| Key | Value |
|---|---|
| _remove_csp_headers | true |
| _stopwatch_token | "e4589b" |
Request Headers
| Header | Value |
|---|---|
| accept | "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" |
| accept-encoding | "gzip, deflate, br, zstd" |
| accept-language | "en-US,en;q=0.9" |
| cache-control | "max-age=0" |
| cf-connecting-ip | "49.76.117.159" |
| cookie | "PHPSESSID=u2lfdcr4410aqrn5clgmf5vq77" |
| forwarded | "for=49.76.117.159;proto=http" |
| forwarded-for | "49.76.117.159" |
| host | "dev.hebu-music.com" |
| sec-ch-ua | "" Not A;Brand";v="99", "Chromium";v="101", "Microsoft Edge";v="101"" |
| sec-ch-ua-mobile | "?0" |
| sec-ch-ua-platform | ""Windows"" |
| sec-fetch-dest | "document" |
| sec-fetch-mode | "navigate" |
| sec-fetch-site | "none" |
| sec-fetch-user | "?1" |
| upgrade-insecure-requests | "1" |
| user-agent | "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| x-api-key | "ZPxxbGfdrUw92tIfhOoDdsHYbwWljt23" |
| x-api-version | "1.0" |
| x-azure-clientip | "49.76.117.159" |
| x-azure-socketip | "49.76.117.159" |
| x-client-ip | "49.76.117.159" |
| x-correlation-id | "KWQs0i8m8BmmGjXyIvYjJIDY4dsaELan" |
| x-forwarded | "49.76.117.159" |
| x-forwarded-for | "49.76.117.159" |
| x-google-real-ip | "49.76.117.159" |
| x-nextjs-data | "1" |
| x-originating-ip | "49.76.117.159" |
| x-php-ob-level | "1" |
| x-real-ip | "49.76.117.159" |
| x-remote-addr | "49.76.117.159" |
| x-remote-ip | "49.76.117.159" |
| x-request-id | "kRv7mFjj5oNfQ4vSxxAZAZTTmP72liun" |
| x-requested-with | "XMLHttpRequest" |
| x-vercel-id | "wuzzodn1k6gv987u" |
| x-vercel-ip-country | "GB" |
| x-vercel-protection-bypass | "1" |
Request Content
Request content not available (it was retrieved as a resource).
Response
Response Headers
| Header | Value |
|---|---|
| cache-control | "no-cache, private" |
| content-type | "text/html; charset=UTF-8" |
| date | "Wed, 07 Jan 2026 09:18:05 GMT" |
| vary | "Accept" |
| x-debug-exception | "No%20route%20found%20for%20%22GET%20https%3A%2F%2Fdev.hebu-music.com%2Fadmin%2Fconfig%22" |
| x-debug-exception-file | "%2Fvar%2Fwww%2Fvhosts%2Fhebu-music.com%2Fdev.hebu-music.com%2Fvendor%2Fsymfony%2Fhttp-kernel%2FEventListener%2FRouterListener.php:127" |
| x-debug-token | "12272d" |
| x-debug-token-link | "https://dev.hebu-music.com/_profiler/908eba" |
| x-previous-debug-token | "908eba" |
| x-robots-tag | "noindex" |
Cookies
Request Cookies
| Key | Value |
|---|---|
| PHPSESSID | "u2lfdcr4410aqrn5clgmf5vq77" |
Response Cookies
No response cookies
Session
Session Metadata
No session metadata
Session Attributes
No session attributes
Session Usage
0
Usages
Stateless check enabled
Session not used.
Flashes
Flashes
No flash messages were created.
Server Parameters
Server Parameters
Defined in .env
| Key | Value |
|---|---|
| APP_AUTHOR | "Michael Hack Software e.K." |
| APP_ENV | "dev" |
| APP_SECRET | "9cd64a60480efc254ee10849c12c1a41" |
| APP_TITLE | "HeBu Shop" |
| APP_URL | "https://www.hebu-music.com" |
| DATABASE_URL | "mysql://hebu_dbu:sqjpqJPrSUBtxzOKKNwQ@127.0.0.1:3306/hebu_dev" |
| DATABASE_VERSION | "10.6.12-MariaDB" |
| DEFAULT_COUNTRY | "84" |
| DEFAULT_DELIVERY_DAYS | "2" |
| DEFAULT_LOCALE | "de" |
| EXCHANGE_RATE_USD | "1.13" |
| EXTERNAL_ALFRED_API_KEY | "be78103939b942f" |
| EXTERNAL_ALFRED_API_USERNAME | "c00108280000" |
| EXTERNAL_ALFRED_FTP_HOST | "ftp1.alfred.com" |
| EXTERNAL_ALFRED_FTP_PASSWORD | "dealerftp" |
| EXTERNAL_ALFRED_FTP_USERNAME | "dealer" |
| EXTERNAL_ALFRED_IP_RANGE | "100.128.0.0" |
| EXTERNAL_ALFRED_SHOP | "14" |
| EXTERNAL_GRAHL_DELIVERY_TIME | "2" |
| EXTERNAL_GRAHL_FTP_HOST | "ftps.grahl-haendlershop.de" |
| EXTERNAL_GRAHL_FTP_PASSWORD | "He_170925" |
| EXTERNAL_GRAHL_FTP_USERNAME | "091410" |
| EXTERNAL_GRAHL_PICTURE_URL | "http://www.notenlink.de/shop/bussbild/" |
| EXTERNAL_HALLEONARD_ENDPOINT | "https://haldms.halleonard.com/dam" |
| EXTERNAL_HALLEONARD_ID | "343" |
| EXTERNAL_HALLEONARD_KEY | "VtsP%R2p_K" |
| EXTERNAL_HALLEONARD_SHOP | "23" |
| EXTERNAL_REIFT_ENDPOINT | "https://catalog.reift.ch/api" |
| EXTERNAL_REIFT_ENDPOINT_DMC | "https://dpm.reift.ch/api" |
| EXTERNAL_REIFT_KEY | "Y82UH2M9sVFZ9yWX6nAqVVsU2kULtVCj" |
| EXTERNAL_REIFT_USERNAME | "hebu" |
| EXTERNAL_SCHOTT_DMC_ENDPOINT | "https://deliverytest.schott-music.com" |
| EXTERNAL_SCHOTT_DMC_FTP_HOST | "213.139.144.254" |
| EXTERNAL_SCHOTT_DMC_FTP_PASSWORD | "3bnHdsgZ&mpsm5eK" |
| EXTERNAL_SCHOTT_DMC_FTP_USERNAME | "hebumusic" |
| EXTERNAL_SCHOTT_DMC_PASSWORD | "v5U4pj(t>Xt+9RZv" |
| EXTERNAL_SCHOTT_DMC_USERNAME | "a.knam@hebu-music.de" |
| EXTERNAL_SCHOTT_FTP_HOST | "213.139.144.254" |
| EXTERNAL_SCHOTT_FTP_PASSWORD | "ESmW886" |
| EXTERNAL_SCHOTT_FTP_USERNAME | "schott_handel_wr" |
| GOOGLE_BADGE | "true" |
| GOOGLE_MERCHANT_ID | "113371582" |
| MAILER_DSN | "smtp://localhost:25" |
| MAIL_CONTACT_FROM | "kontakt@hebu-music.com" |
| MAIL_CONTACT_TO | "service@mh-s.de" |
| MAIL_ERROR | "service@mh-s.de" |
| MAIL_FROM | "shop@hebu-music.com" |
| ORGAMON_ARTIKEL_VERSION_R_EINZELSTIMME | "3" |
| ORGAMON_ARTIKEL_VERSION_R_MP3 | "9" |
| ORGAMON_ARTIKEL_VERSION_R_PDF | "10" |
| PAYPAL_ACTIVE | "1" |
| PAYPAL_CLIENTID | "AbnD15O5JjJtV1IAVcjJTUF67wmj2oCz3DLiB2ssWV7xDLzd-MPzKAZuz6w65zH8BZ20QajHYbY0MStd" |
| PAYPAL_SANDBOX | "1" |
| PAYPAL_SECRET | "ENUL-IhOhVwDbrb0dwLjuplFkhatOt2GleiYkt3YLZBeBiOnb2nKUQYTJmnFa-Zk0P4uNLLFiA8RAAlD" |
| PUBLISHER_ALFRED_RID | "696" |
| PUBLISHER_KALMUS_RID | "2399557" |
| PUBLISHER_REIFT_RID | "296" |
| PUBLISHER_SCHOTT_RID | "438" |
| VAT_ID | "DE301347170" |
Defined as regular env variables
| Key | Value |
|---|---|
"dev" |
|
| APP_DEBUG | "1" |
| CONTENT_LENGTH | "" |
| CONTENT_TYPE | "" |
| DOCUMENT_ROOT | "/var/www/vhosts/hebu-music.com/dev.hebu-music.com/public" |
| DOCUMENT_URI | "/index.php" |
| FCGI_ROLE | "RESPONDER" |
| GATEWAY_INTERFACE | "CGI/1.1" |
| HOME | "/var/www/vhosts/hebu-music.com" |
| HTTPS | "on" |
| HTTP_ACCEPT | "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" |
| HTTP_ACCEPT_ENCODING | "gzip, deflate, br, zstd" |
| HTTP_ACCEPT_LANGUAGE | "en-US,en;q=0.9" |
| HTTP_CACHE_CONTROL | "max-age=0" |
| HTTP_CF_CONNECTING_IP | "49.76.117.159" |
| HTTP_COOKIE | "PHPSESSID=u2lfdcr4410aqrn5clgmf5vq77" |
| HTTP_FORWARDED | "for=49.76.117.159;proto=http" |
| HTTP_FORWARDED_FOR | "49.76.117.159" |
| HTTP_HOST | "dev.hebu-music.com" |
| HTTP_SEC_CH_UA | "" Not A;Brand";v="99", "Chromium";v="101", "Microsoft Edge";v="101"" |
| HTTP_SEC_CH_UA_MOBILE | "?0" |
| HTTP_SEC_CH_UA_PLATFORM | ""Windows"" |
| HTTP_SEC_FETCH_DEST | "document" |
| HTTP_SEC_FETCH_MODE | "navigate" |
| HTTP_SEC_FETCH_SITE | "none" |
| HTTP_SEC_FETCH_USER | "?1" |
| HTTP_UPGRADE_INSECURE_REQUESTS | "1" |
| HTTP_USER_AGENT | "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" |
| HTTP_X_API_KEY | "ZPxxbGfdrUw92tIfhOoDdsHYbwWljt23" |
| HTTP_X_API_VERSION | "1.0" |
| HTTP_X_AZURE_CLIENTIP | "49.76.117.159" |
| HTTP_X_AZURE_SOCKETIP | "49.76.117.159" |
| HTTP_X_CLIENT_IP | "49.76.117.159" |
| HTTP_X_CORRELATION_ID | "KWQs0i8m8BmmGjXyIvYjJIDY4dsaELan" |
| HTTP_X_FORWARDED | "49.76.117.159" |
| HTTP_X_FORWARDED_FOR | "49.76.117.159" |
| HTTP_X_GOOGLE_REAL_IP | "49.76.117.159" |
| HTTP_X_NEXTJS_DATA | "1" |
| HTTP_X_ORIGINATING_IP | "49.76.117.159" |
| HTTP_X_REAL_IP | "49.76.117.159" |
| HTTP_X_REMOTE_ADDR | "49.76.117.159" |
| HTTP_X_REMOTE_IP | "49.76.117.159" |
| HTTP_X_REQUESTED_WITH | "XMLHttpRequest" |
| HTTP_X_REQUEST_ID | "kRv7mFjj5oNfQ4vSxxAZAZTTmP72liun" |
| HTTP_X_VERCEL_ID | "wuzzodn1k6gv987u" |
| HTTP_X_VERCEL_IP_COUNTRY | "GB" |
| HTTP_X_VERCEL_PROTECTION_BYPASS | "1" |
| PATH_INFO | "" |
| PHP_SELF | "/index.php" |
| QUERY_STRING | "cmd=cat%20/root/.aws/credentials|echo%20TEST_RCE_2025" |
| REDIRECT_STATUS | "200" |
| REMOTE_ADDR | "213.111.152.40" |
| REMOTE_PORT | "43190" |
| REQUEST_METHOD | "GET" |
| REQUEST_SCHEME | "https" |
| REQUEST_TIME | 1767777485 |
| REQUEST_TIME_FLOAT | 1767777485.3014 |
| REQUEST_URI | "/admin/config?cmd=cat%20/root/.aws/credentials|echo%20TEST_RCE_2025" |
| SCRIPT_FILENAME | "/var/www/vhosts/hebu-music.com/dev.hebu-music.com/public/index.php" |
| SCRIPT_NAME | "/index.php" |
| SERVER_ADDR | "194.164.202.94" |
| SERVER_NAME | "dev.hebu-music.com" |
| SERVER_PORT | "443" |
| SERVER_PROTOCOL | "HTTP/2.0" |
| SERVER_SOFTWARE | "nginx/1.28.0" |
| SYMFONY_DOTENV_VARS | "APP_AUTHOR,APP_ENV,APP_SECRET,APP_TITLE,APP_URL,DATABASE_VERSION,DEFAULT_DELIVERY_DAYS,MAIL_ERROR,MAIL_FROM,MAIL_CONTACT_FROM,MAIL_CONTACT_TO,GOOGLE_BADGE,GOOGLE_MERCHANT_ID,ORGAMON_ARTIKEL_VERSION_R_EINZELSTIMME,ORGAMON_ARTIKEL_VERSION_R_MP3,ORGAMON_ARTIKEL_VERSION_R_PDF,EXCHANGE_RATE_USD,EXTERNAL_ALFRED_SHOP,EXTERNAL_ALFRED_FTP_HOST,EXTERNAL_ALFRED_FTP_USERNAME,EXTERNAL_ALFRED_FTP_PASSWORD,EXTERNAL_ALFRED_API_USERNAME,EXTERNAL_ALFRED_API_KEY,EXTERNAL_ALFRED_IP_RANGE,EXTERNAL_GRAHL_DELIVERY_TIME,EXTERNAL_GRAHL_FTP_HOST,EXTERNAL_GRAHL_FTP_USERNAME,EXTERNAL_GRAHL_FTP_PASSWORD,EXTERNAL_GRAHL_PICTURE_URL,EXTERNAL_HALLEONARD_SHOP,EXTERNAL_HALLEONARD_ID,EXTERNAL_HALLEONARD_KEY,EXTERNAL_HALLEONARD_ENDPOINT,EXTERNAL_REIFT_ENDPOINT,EXTERNAL_REIFT_ENDPOINT_DMC,EXTERNAL_REIFT_USERNAME,EXTERNAL_REIFT_KEY,EXTERNAL_SCHOTT_FTP_HOST,EXTERNAL_SCHOTT_FTP_USERNAME,EXTERNAL_SCHOTT_FTP_PASSWORD,EXTERNAL_SCHOTT_DMC_FTP_HOST,EXTERNAL_SCHOTT_DMC_FTP_USERNAME,EXTERNAL_SCHOTT_DMC_FTP_PASSWORD,EXTERNAL_SCHOTT_DMC_ENDPOINT,EXTERNAL_SCHOTT_DMC_USERNAME,EXTERNAL_SCHOTT_DMC_PASSWORD,PAYPAL_ACTIVE,PAYPAL_SANDBOX,PAYPAL_CLIENTID,PAYPAL_SECRET,DEFAULT_COUNTRY,DEFAULT_LOCALE,PUBLISHER_ALFRED_RID,PUBLISHER_KALMUS_RID,PUBLISHER_REIFT_RID,PUBLISHER_SCHOTT_RID,VAT_ID,DATABASE_URL,MAILER_DSN" |
| USER | "hebu-music" |
Sub Requests 1
ErrorController (token = 908eba)
| Key | Value |
|---|---|
| _controller | "error_controller" |
| _stopwatch_token | "2c8b1e" |
| exception | Symfony\Component\HttpKernel\Exception\NotFoundHttpException {#450 #message: "No route found for "GET https://dev.hebu-music.com/admin/config"" #code: 0 #file: "/var/www/vhosts/hebu-music.com/dev.hebu-music.com/vendor/symfony/http-kernel/EventListener/RouterListener.php" #line: 127 -previous: Symfony\Component\Routing\Exception\ResourceNotFoundException {#395 …} -statusCode: 404 -headers: [] : { { Symfony\Component\HttpKernel\EventListener\RouterListener->onKernelRequest(RequestEvent $event): void … › › |
| logger | Symfony\Bridge\Monolog\Processor\DebugProcessor {#336 -records: [ 4 => [ [ "timestamp" => 1767777485 "timestamp_rfc3339" => "2026-01-07T09:18:05.415+00:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\DebugHandlersListener::configure" ] "channel" => "event" ] [ "timestamp" => 1767777485 "timestamp_rfc3339" => "2026-01-07T09:18:05.415+00:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\ValidateRequestListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1767777485 "timestamp_rfc3339" => "2026-01-07T09:18:05.415+00:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\SessionListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1767777485 "timestamp_rfc3339" => "2026-01-07T09:18:05.415+00:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\LocaleListener::setDefaultLocale" ] "channel" => "event" ] [ "timestamp" => 1767777485 "timestamp_rfc3339" => "2026-01-07T09:18:05.415+00:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\RouterListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1767777485 "timestamp_rfc3339" => "2026-01-07T09:18:05.419+00:00" "message" => "Uncaught PHP Exception Symfony\Component\HttpKernel\Exception\NotFoundHttpException: "No route found for "GET https://dev.hebu-music.com/admin/config"" at RouterListener.php line 127" "priority" => 400 "priorityName" => "ERROR" "context" => [ "exception" => Symfony\Component\HttpKernel\Exception\NotFoundHttpException {#450 #message: "No route found for "GET https://dev.hebu-music.com/admin/config"" #code: 0 #file: "/var/www/vhosts/hebu-music.com/dev.hebu-music.com/vendor/symfony/http-kernel/EventListener/RouterListener.php" #line: 127 -previous: Symfony\Component\Routing\Exception\ResourceNotFoundException {#395 …} -statusCode: 404 -headers: [] : { { Symfony\Component\HttpKernel\EventListener\RouterListener->onKernelRequest(RequestEvent $event): void … › › |