A potentially dangerous Request.QueryString value was detected from the client (="...create /,/<?echo(md5("hi"));?>...").

System.Web.HttpRequestValidationException: A potentially dangerous Request.QueryString value was detected from the client (="...create /,/<?echo(md5("hi"));?>...").

System.Web.HttpRequestValidationException (0x80004005): A potentially dangerous Request.QueryString value was detected from the client (="...create /,/<?echo(md5("hi"));?>...").
   at System.Web.HttpRequest.ValidateString(String value, String collectionKey, RequestValidationSource requestCollection)
   at System.Web.HttpRequest.ValidateHttpValueCollection(HttpValueCollection collection, RequestValidationSource requestCollection)
   at System.Web.HttpRequest.get_QueryString()
   at DevExpress.Web.BinaryStorageSubscriber.RequestRecipient(HttpRequest request, RequestEvent requestEvent)
   at DevExpress.Web.ASPxHttpHandlerModule.ProcessRequestCore(RequestEvent requestEvent)
   at DevExpress.Web.ASPxHttpHandlerModule.BeginRequestHandler(Object sender, EventArgs e)
   at System.Web.HttpApplication.SyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()
   at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously)
		

Logged on Sunday, May 26, 2024 at 8:05:17 PM

See also:

Server Variables

NameValue
ALL_HTTPHTTP_CONNECTION:keep-alive HTTP_ACCEPT:*/* HTTP_HOST:20.49.30.248:80 HTTP_USER_AGENT:Custom-AsyncHttpClient HTTP_UPGRADE_INSECURE_REQUESTS:1
ALL_RAWConnection: keep-alive Accept: */* Host: 20.49.30.248:80 User-Agent: Custom-AsyncHttpClient Upgrade-Insecure-Requests: 1
APPL_MD_PATH/LM/W3SVC/1/ROOT
APPL_PHYSICAL_PATHC:\inetpub\wwwroot\
AUTH_PASSWORD*****
AUTH_TYPE
AUTH_USER
CERT_COOKIE
CERT_FLAGS
CERT_ISSUER
CERT_KEYSIZE
CERT_SECRETKEYSIZE
CERT_SERIALNUMBER
CERT_SERVER_ISSUER
CERT_SERVER_SUBJECT
CERT_SUBJECT
CONTENT_LENGTH0
CONTENT_TYPE
GATEWAY_INTERFACECGI/1.1
HTTP_ACCEPT*/*
HTTP_CONNECTIONkeep-alive
HTTP_HOST20.49.30.248:80
HTTP_UPGRADE_INSECURE_REQUESTS1
HTTP_USER_AGENTCustom-AsyncHttpClient
HTTPSoff
HTTPS_KEYSIZE
HTTPS_SECRETKEYSIZE
HTTPS_SERVER_ISSUER
HTTPS_SERVER_SUBJECT
INSTANCE_ID1
INSTANCE_META_PATH/LM/W3SVC/1
LOCAL_ADDR10.3.1.4
LOGON_USER
PATH_INFO/index.php
PATH_TRANSLATEDC:\inetpub\wwwroot\index.php
QUERY_STRINGlang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?echo(md5("hi"));?>+/tmp/index1.php
REMOTE_ADDR156.248.111.1
REMOTE_HOST156.248.111.1
REMOTE_PORT35540
REMOTE_USER
REQUEST_METHODGET
SCRIPT_NAME/index.php
SERVER_NAME20.49.30.248
SERVER_PORT80
SERVER_PORT_SECURE0
SERVER_PROTOCOLHTTP/1.1
SERVER_SOFTWAREMicrosoft-IIS/10.0
URL/index.php