An attacker can give values like Paulos;ls la for windows systems and execute the ls la command. Null byte can be achieved by writing some regular expression with the help of our dear friend, the null byte. In some functions that are used to include the code inside the page, if an untusted file is used to dynamically include files inside a file, it would result in the same vulnerability. There is no function designed in PHP to properly escape eval.”]
Source: http://www.rafayhackingarticles.net/2014/08/remote-code-execution-in-php-explained.html