Sends the actual Form API exploit payload with a harmless echo canary. If the canary appears in the response, the server executed attacker-controlled code.
Is your app exploitable through CVE-2018-7600?