Now, if one of the following is true (and thats quite common):
* The webserver has access to sensitive data
* The operating system has a bug that allows getting higher privileges as an unprivileged user without credentials
The machine is hacked and broken. (either the sensitive data can be extracted or the machine can be reconfigured)
This is why remote code execution is rated very high as a vulnerability.
A common way to prove this is by running a command that doesn't do any direct harm. uptime is quite usual, reading /etc/passwd is also quite usual.