LFI vs RFI: From File Disclosure to Remote Code Execution
File inclusion bugs come in two flavors. Local File Inclusion pulls a server-side file into execution — leaking source and secrets, and escalating to code execution through php://filter, log poisoning or /proc/self/environ. Remote File Inclusion pulls in an attacker-hosted URL and runs it outright. The dividing line is include() versus a read-only readfile(), and the fix is to keep user input away from both.