Remote File Inclusion is the most common vulnerability found in many web servers. If the remote file execution is performed successfully, we can get control over the server and make it execute any command of our wish. So how exactly we can do that?

First we need to know the websites which are vulnerable to this, using the following google dork:

“inurl:index.php?page=”

We get number of websites listed of the form: