GET https://www.test.fleetmater.optimumci.com/?download=..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00.jpg

HomeController :: index

Request

GET Parameters

Key Value
download
"../../../../../../etc/passwd\x00.jpg"

POST Parameters

No POST parameters

Uploaded Files

No files were uploaded

Request Attributes

Key Value
_access_control_attributes
null
_controller
"App\Controller\Domain\HomeController::index"
_firewall_context
"security.firewall.map.context.main"
_route
"app_domain_home"
_route_params
[]
_stopwatch_token
"baded0"

Request Headers

Header Value
accept
"*/*"
accept-encoding
"gzip, br, zstd, deflate"
host
"www.test.fleetmater.optimumci.com"
user-agent
"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)"
x-php-ob-level
"1"

Request Content

Request content not available (it was retrieved as a resource).

Response

Response Headers

Header Value
cache-control
"no-cache, private"
content-type
"text/html; charset=utf-8"
date
"Thu, 25 Jun 2026 20:02:06 GMT"
location
"/login"
x-debug-token
"65ddc8"

Cookies

Request Cookies

No request cookies

Response Cookies

No response cookies

Session

Session Metadata

No session metadata

Session Attributes

No session attributes

Session Usage

0 Usages
Stateless check enabled

Session not used.

Flashes

Flashes

No flash messages were created.

Server Parameters

Server Parameters

Defined in .env

Key Value
API_SYNC_EMAIL
"api@sifogroup.com"
API_SYNC_URI
"https://axiumv2.optimumci.com/api"
APP_ENV
"dev"
APP_SECRET
"909f38cb49ab4208b9b48ac6e1e7582f"
AUTH0_CLIENT_ID
"eZ3ePbY4W9jSodJxSCfFvQwK9HNTJyeL"
AUTH0_CLIENT_SECRET
"FTMTzHh4wviQSz8u0T4LWhONU2XM9P0NkykKkoV1tkLnJbdjC8MEkXWZjQWhweu5"
AUTH0_DOMAIN
"optimum-solutions.eu.auth0.com"
AUTH0_M2M_CLIENT_ID
"WjXhET0xdWbsbDZJelC0eKozOgZIJLfx"
AUTH0_M2M_CLIENT_SECRET
"Fv64qfUNo7K-zWu0DVEPSkOnkPPGAxUyMQ3Y1Uqvf3fN2MnLQY60VYjRCTlhS_Sn"
CORS_ALLOW_ORIGIN
"^https?://(localhost|127\.0\.0\.1)(:[0-9]+)?$"
DATABASE_URL
"mysql://root:3b8d0e917f5bf39e@127.0.0.1:3307/test_fleetmaster_db?serverVersion=5.7"
GOOGLE_API_KEY
"AIzaSyA53dQyEQX1TkKiVU-YNyFPhlklfMafEEw"
JWT_PASSPHRASE
"e1e1a6e2d6e0fadd2829fcbbe89f13e91aad7b48a1723ed3c26489d1db42d453"
JWT_PUBLIC_KEY
"%kernel.project_dir%/config/jwt/public.pem"
JWT_SECRET_KEY
"%kernel.project_dir%/config/jwt/private.pem"
SYMFONY_PROFILER
"0"

Defined as regular env variables

Key Value
APP_DEBUG
"1"
CONTENT_LENGTH
""
CONTENT_TYPE
""
DOCUMENT_ROOT
"/www/wwwroot/fleetmaster-test/public"
DOCUMENT_URI
"/index.php"
FCGI_ROLE
"RESPONDER"
GATEWAY_INTERFACE
"CGI/1.1"
HOME
"/home/www"
HTTPS
"on"
HTTP_ACCEPT
"*/*"
HTTP_ACCEPT_ENCODING
"gzip, br, zstd, deflate"
HTTP_HOST
"www.test.fleetmater.optimumci.com"
HTTP_USER_AGENT
"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)"
PATH_INFO
""
PHP_SELF
"/index.php"
QUERY_STRING
"download=..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00.jpg"
REDIRECT_STATUS
"200"
REMOTE_ADDR
"216.73.216.205"
REMOTE_PORT
"10731"
REQUEST_METHOD
"GET"
REQUEST_SCHEME
"https"
REQUEST_TIME
1782417725
REQUEST_TIME_FLOAT
1782417725.7567
REQUEST_URI
"/?download=..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00.jpg"
SCRIPT_FILENAME
"/www/wwwroot/fleetmaster-test/public/index.php"
SCRIPT_NAME
"/index.php"
SERVER_ADDR
"37.59.125.27"
SERVER_NAME
"www.test.fleetmater.optimumci.com"
SERVER_PORT
"443"
SERVER_PROTOCOL
"HTTP/2.0"
SERVER_SOFTWARE
"nginx/1.24.0"
SYMFONY_DOTENV_VARS
"APP_ENV,APP_SECRET,SYMFONY_PROFILER,DATABASE_URL,GOOGLE_API_KEY,API_SYNC_URI,API_SYNC_EMAIL,JWT_SECRET_KEY,JWT_PUBLIC_KEY,JWT_PASSPHRASE,CORS_ALLOW_ORIGIN,AUTH0_CLIENT_ID,AUTH0_DOMAIN,AUTH0_CLIENT_SECRET,AUTH0_M2M_CLIENT_ID,AUTH0_M2M_CLIENT_SECRET"
USER
"www"