PHP Webshell Upload via HTTP POST with Eval/System Functions

Detects HTTP POST requests containing multipart form data that include suspicious PHP functions commonly associated with webshells, such as eval(), base64_decode(), system(), or passthru(). This indicates a potential attempt to upload or execute a malicious PHP script on a web server.