System.Web.HttpRequestValidationException: A potentially dangerous Request.QueryString value was detected from the client (="...create /,/<?echo(md5("hi"));?>...").
System.Web.HttpRequestValidationException (0x80004005): A potentially dangerous Request.QueryString value was detected from the client (="...create /,/<?echo(md5("hi"));?>...").
at System.Web.HttpRequest.ValidateString(String value, String collectionKey, RequestValidationSource requestCollection)
at System.Web.HttpRequest.ValidateHttpValueCollection(HttpValueCollection collection, RequestValidationSource requestCollection)
at System.Web.HttpRequest.get_QueryString()
at DevExpress.Web.BinaryStorageSubscriber.RequestRecipient(HttpRequest request, RequestEvent requestEvent)
at DevExpress.Web.ASPxHttpHandlerModule.ProcessRequestCore(RequestEvent requestEvent)
at DevExpress.Web.ASPxHttpHandlerModule.BeginRequestHandler(Object sender, EventArgs e)
at System.Web.HttpApplication.SyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()
at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
Logged on Sunday, May 26, 2024 at 8:05:17 PM
See also:
Server Variables
| Name | Value |
|---|---|
| ALL_HTTP | HTTP_CONNECTION:keep-alive HTTP_ACCEPT:*/* HTTP_HOST:20.49.30.248:80 HTTP_USER_AGENT:Custom-AsyncHttpClient HTTP_UPGRADE_INSECURE_REQUESTS:1 |
| ALL_RAW | Connection: keep-alive Accept: */* Host: 20.49.30.248:80 User-Agent: Custom-AsyncHttpClient Upgrade-Insecure-Requests: 1 |
| APPL_MD_PATH | /LM/W3SVC/1/ROOT |
| APPL_PHYSICAL_PATH | C:\inetpub\wwwroot\ |
| AUTH_PASSWORD | ***** |
| AUTH_TYPE | |
| AUTH_USER | |
| CERT_COOKIE | |
| CERT_FLAGS | |
| CERT_ISSUER | |
| CERT_KEYSIZE | |
| CERT_SECRETKEYSIZE | |
| CERT_SERIALNUMBER | |
| CERT_SERVER_ISSUER | |
| CERT_SERVER_SUBJECT | |
| CERT_SUBJECT | |
| CONTENT_LENGTH | 0 |
| CONTENT_TYPE | |
| GATEWAY_INTERFACE | CGI/1.1 |
| HTTP_ACCEPT | */* |
| HTTP_CONNECTION | keep-alive |
| HTTP_HOST | 20.49.30.248:80 |
| HTTP_UPGRADE_INSECURE_REQUESTS | 1 |
| HTTP_USER_AGENT | Custom-AsyncHttpClient |
| HTTPS | off |
| HTTPS_KEYSIZE | |
| HTTPS_SECRETKEYSIZE | |
| HTTPS_SERVER_ISSUER | |
| HTTPS_SERVER_SUBJECT | |
| INSTANCE_ID | 1 |
| INSTANCE_META_PATH | /LM/W3SVC/1 |
| LOCAL_ADDR | 10.3.1.4 |
| LOGON_USER | |
| PATH_INFO | /index.php |
| PATH_TRANSLATED | C:\inetpub\wwwroot\index.php |
| QUERY_STRING | lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?echo(md5("hi"));?>+/tmp/index1.php |
| REMOTE_ADDR | 156.248.111.1 |
| REMOTE_HOST | 156.248.111.1 |
| REMOTE_PORT | 35540 |
| REMOTE_USER | |
| REQUEST_METHOD | GET |
| SCRIPT_NAME | /index.php |
| SERVER_NAME | 20.49.30.248 |
| SERVER_PORT | 80 |
| SERVER_PORT_SECURE | 0 |
| SERVER_PROTOCOL | HTTP/1.1 |
| SERVER_SOFTWARE | Microsoft-IIS/10.0 |
| URL | /index.php |