Php 5.3.10 Exploit -

However, the RCE payload is specific. Spaces are not allowed in URLs naturally, so they must be replaced with + or %20 .

Arbitrary PHP code execution on the server, with the privileges of the web server user. php 5.3.10 exploit