Request / Response
Request
GET Parameters
| Key | Value |
|---|---|
| action | "the_champ_sharing_count" |
| urls | [
"<img src=x onerror=alert(document.domain)>"
] |
POST Parameters
No POST parameters
Uploaded Files
No files were uploaded
Request Attributes
| Key | Value |
|---|---|
| _remove_csp_headers | true |
| _stopwatch_token | "458f8c" |
Request Headers
| Header | Value |
|---|---|
| accept-encoding | "gzip,deflate" |
| host | "agacat-preprod.ip2i.in2p3.fr" |
| user-agent | "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Chrome/119.0.6045.214 Safari/537.36" |
| x-forwarded-for | "18.207.89.138" |
| x-forwarded-host | "agacat-preprod.ip2i.in2p3.fr" |
| x-forwarded-port | "443" |
| x-forwarded-proto | "https" |
| x-forwarded-server | "ad9ce4771f48" |
| x-php-ob-level | "0" |
| x-real-ip | "18.207.89.138" |
Request Content
Request content not available (it was retrieved as a resource).
Response
Response Headers
| Header | Value |
|---|---|
| cache-control | "no-cache, private" |
| content-type | "text/html; charset=UTF-8" |
| date | "Thu, 18 Jun 2026 12:14:02 GMT" |
| vary | "Accept" |
| x-debug-exception | "No%20route%20found%20for%20%22GET%20https%3A%2F%2Fagacat-preprod.ip2i.in2p3.fr%2Fwp-admin%2Fadmin-ajax.php%22" |
| x-debug-exception-file | "%2Fvar%2Fwww%2Fhtml%2Fvendor%2Fsymfony%2Fhttp-kernel%2FEventListener%2FRouterListener.php:156" |
| x-debug-token | "7587f3" |
| x-debug-token-link | "https://agacat-preprod.ip2i.in2p3.fr/_profiler/f63a03" |
| x-previous-debug-token | "f63a03" |
| x-robots-tag | "noindex" |
Cookies
Request Cookies
No request cookies
Response Cookies
No response cookies
Session
Session Metadata
No session metadata
Session Attributes
No session attributes
Session Usage
0
Usages
Stateless check enabled
Session not used.
Flashes
Flashes
No flash messages were created.
Server Parameters
Server Parameters
Defined in .env
| Key | Value |
|---|---|
| APP_SECRET | "8084213b53e38106abac7547202a8312" |
| APP_VERSION | "v0.0.0-dev" |
| DATABASE_URL | "postgresql://catalogue:catalogue@db:5432/catalogue?serverVersion=16&charset=utf8" |
| DEFAULT_URI | "http://localhost:8000" |
| MAILER_DSN | "null://null" |
| MESSENGER_TRANSPORT_DSN | "doctrine://default?auto_setup=0" |
| OAUTH_INDIGO_ACCESS_TOKEN_URL | "https://iam-agata.ijclab.in2p3.fr/token" |
| OAUTH_INDIGO_AUTHORIZE_URL | "https://iam-agata.ijclab.in2p3.fr/authorize" |
| OAUTH_INDIGO_REDIRECT_URI | "https://agacat-preprod.ip2i.in2p3.fr/connect/indigo/check" |
| OAUTH_INDIGO_RESOURCE_OWNER_URL | "https://iam-agata.ijclab.in2p3.fr/userinfo" |
Defined as regular env variables
| Key | Value |
|---|---|
| APP_DEBUG | "1" |
| APP_ENV | "dev" |
| APP_PROJECT_DIR | "/var/www/html" |
| APP_RUNTIME | "Symfony\Component\Runtime\SymfonyRuntime" |
| APP_RUNTIME_OPTIONS | [ "project_dir" => "/var/www/html" ] |
| AUTH_TYPE | "" |
| COMPOSER_ALLOW_SUPERUSER | "1" |
| CONTENT_LENGTH | "" |
| CONTENT_TYPE | "" |
| DOCUMENT_ROOT | "/var/www/html/public" |
| DOCUMENT_URI | "/index.php" |
| GATEWAY_INTERFACE | "CGI/1.1" |
| GODEBUG | "cgocheck=0" |
| GOTRACEBACK | "none" |
| GPG_KEYS | "AFD8691FDAEDF03BDF6E460563F15A9B715376CA 9D7F99A0CB8F05C8A6958D6256A97AF7600A39A6 0616E93D95AF471243E26761770426E17EBBB3DD" |
| HOME | "/root" |
| HOSTNAME | "2e7b117159c1" |
| HTTPS | "" |
| HTTP_ACCEPT_ENCODING | "gzip,deflate" |
| HTTP_HOST | "agacat-preprod.ip2i.in2p3.fr" |
| HTTP_USER_AGENT | "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Chrome/119.0.6045.214 Safari/537.36" |
| HTTP_X_FORWARDED_FOR | "18.207.89.138" |
| HTTP_X_FORWARDED_HOST | "agacat-preprod.ip2i.in2p3.fr" |
| HTTP_X_FORWARDED_PORT | "443" |
| HTTP_X_FORWARDED_PROTO | "https" |
| HTTP_X_FORWARDED_SERVER | "ad9ce4771f48" |
| HTTP_X_REAL_IP | "18.207.89.138" |
| IMAGE_TAG | "benchmarks" |
| LC_CTYPE | "C.UTF-8" |
| OAUTH_INDIGO_CLIENT_ID | "0dc98689-aa9b-40da-a685-9c6163aa9fcc" |
| OAUTH_INDIGO_CLIENT_SECRET | "AIAI7TOYvQiarZXTsm-z8zhchprb9XOIMS5FmYit2YxIe-SfCF2FzsUy7ML4w9T64LUJ0uVTXcxRovO-ERn6pTI" |
| PATH | "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" |
| PATH_INFO | "" |
| PHPIZE_DEPS | "autoconf \t\tdpkg-dev \t\tfile \t\tg++ \t\tgcc \t\tlibc-dev \t\tmake \t\tpkg-config \t\tre2c" |
| PHP_ASC_URL | "https://www.php.net/distributions/php-8.4.21.tar.xz.asc" |
| PHP_CFLAGS | "-fstack-protector-strong -fpic -fpie -O2 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" |
| PHP_CPPFLAGS | "-fstack-protector-strong -fpic -fpie -O2 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" |
| PHP_INI_DIR | "/usr/local/etc/php" |
| PHP_LDFLAGS | "-Wl,-O1 -pie" |
| PHP_SELF | "/index.php" |
| PHP_SHA256 | "7cf5d8ab12c3b2016875bcfaec71bef1ef0b07bed6148f2c447577074431f984" |
| PHP_URL | "https://www.php.net/distributions/php-8.4.21.tar.xz" |
| PHP_VERSION | "8.4.21" |
| PWD | "/var/www/html" |
| QUERY_STRING | "action=the_champ_sharing_count&urls[0]=%3Cimg%20src%3Dx%20onerror%3Dalert(document.domain)%3E" |
| REMOTE_ADDR | "10.10.0.224" |
| REMOTE_HOST | "10.10.0.224" |
| REMOTE_IDENT | "" |
| REMOTE_PORT | "58602" |
| REQUEST_METHOD | "GET" |
| REQUEST_SCHEME | "http" |
| REQUEST_TIME | 1781784842 |
| REQUEST_TIME_FLOAT | 1781784842.0273 |
| REQUEST_URI | "/wp-admin/admin-ajax.php?action=the_champ_sharing_count&urls[0]=%3Cimg%20src%3Dx%20onerror%3Dalert(document.domain)%3E" |
| SCRIPT_FILENAME | "/var/www/html/public/index.php" |
| SCRIPT_NAME | "/index.php" |
| SERVER_NAME | "agacat-preprod.ip2i.in2p3.fr" |
| SERVER_PORT | "80" |
| SERVER_PROTOCOL | "HTTP/1.1" |
| SERVER_SOFTWARE | "FrankenPHP" |
| SSL_CIPHER | "" |
| SSL_PROTOCOL | "" |
| SUPERVISOR_ENABLED | "1" |
| SUPERVISOR_GROUP_NAME | "frankenphp" |
| SUPERVISOR_PROCESS_NAME | "frankenphp" |
| SUPERVISOR_SERVER_URL | "unix:///var/run/supervisor.sock" |
| SYMFONY_DOTENV_PATH | "/var/www/html/.env" |
| SYMFONY_DOTENV_VARS | "APP_VERSION,APP_SECRET,DEFAULT_URI,DATABASE_URL,OAUTH_INDIGO_AUTHORIZE_URL,OAUTH_INDIGO_ACCESS_TOKEN_URL,OAUTH_INDIGO_RESOURCE_OWNER_URL,OAUTH_INDIGO_REDIRECT_URI,MESSENGER_TRANSPORT_DSN,MAILER_DSN" |
| TZ | "Europe/Paris" |
| WWWDATA_UID | "5052" |
| XDG_CONFIG_HOME | "/config" |
| XDG_DATA_HOME | "/data" |
| argc | 0 |
| argv | [] |