During a CTF with a LFI vulnerability. I found this article talking about getting a RCE from a LFI using the temporary file of php.

So I think It is a good idea to share this article here.