Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-9841

Quick assessment

Affected
n/a n/a
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TYPO3是瑞士TYPO3协会维护的一套免费开源的内容管理系统。PHPUnit是其中的一个基于PHP的测试框架。 PHPUnit 4.8.28之前的版本和5.6.3之前的5.x版本中的Util/PHP/eval-stdin.php文件存在安全漏洞。远程攻击者可通过发送以‘<?php’字符串开头的HTTP POST数据利用该漏洞执行任意PHP代码。

AI Predicted 9.8 Difficulty: Trivial KEV EPSS 100.00% · P100

Public Exploits 2

ExploitDB · 1 EDB-50702 [webapps]
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-9841

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
PHPUnit 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TYPO3是瑞士TYPO3协会维护的一套免费开源的内容管理系统。PHPUnit是其中的一个基于PHP的测试框架。 PHPUnit 4.8.28之前的版本和5.6.3之前的5.x版本中的Util/PHP/eval-stdin.php文件存在安全漏洞。远程攻击者可通过发送以‘<?php’字符串开头的HTTP POST数据利用该漏洞执行任意PHP代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2017-9841

# POC Description Source Link Shenlong Link
1 CVE-2017-9841 detector script https://github.com/mbrasile/CVE-2017-9841 POC Details
2 Tool to try multiple paths for PHPunit RCE CVE-2017-9841 https://github.com/RandomRobbieBF/phpunit-brute POC Details
3 None https://github.com/cyberharsh/Php-unit-CVE-2017-9841 POC Details
4 (CVE-2017-9841) PHPUnit_eval-stdin_php Remote Code Execution https://github.com/ludy-dev/PHPUnit_eval-stdin_RCE POC Details
5 Masscanner for Laravel phpunit RCE CVE-2017-9841 https://github.com/incogbyte/laravel-phpunit-rce-masscaner POC Details
6 RCE exploit for PHP Unit 5.6.2 https://github.com/akr3ch/CVE-2017-9841 POC Details
7 phpunit-shell | CVE_2017-9841 https://github.com/p1ckzi/CVE-2017-9841 POC Details
8 CVE-2017-9841批量扫描及利用脚本。PHPUnit是其中的一个基于PHP的测试框架。 PHPUnit 4.8.28之前的版本和5.6.3之前的5.x版本中的Util/PHP/eval-stdin.php文件存在安全漏洞。远程攻击者可通过发送以‘<?php’字符串开头的HTTP POST数据利用该漏洞执行任意PHP代码。 https://github.com/jax7sec/CVE-2017-9841 POC Details
9 None https://github.com/yoloskr/CVE-2017-9841-Scan POC Details
10 Automated Exploit for CVE-2017-9841 (eval-stdin.php vulnerable file) https://github.com/mileticluka1/eval-stdin POC Details
11 None https://github.com/Jhonsonwannaa/CVE-2017-9841- POC Details
12 PHPunit Checker CVE-2017-9841 By MrMad https://github.com/MadExploits/PHPunit-Exploit POC Details
13 A Tool for scanning CVE-2017-9841 with multithread https://github.com/MrG3P5/CVE-2017-9841 POC Details
14 PHPUnit RCE https://github.com/Chocapikk/CVE-2017-9841 POC Details
15 None https://github.com/omgdomgd/CVE-2017-9841-Scan POC Details
16 None https://github.com/dream434/CVE-2017-9841- POC Details
17 CVE-2017-9841 https://github.com/dream434/CVE-2017-9841 POC Details
18 PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring via Util/PHP/eval-stdin.php , as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-9841.yaml POC Details
19 None https://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E6%A1%86%E6%9E%B6%E6%BC%8F%E6%B4%9E/PHPUnit%20eval-stdin.php%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2017-9841.md POC Details
20 None https://github.com/chaitin/xray-plugins/blob/main/poc/manual/phpunit-cve-2017-9841-rce.yml POC Details
21 https://github.com/vulhub/vulhub/blob/master/phpunit/CVE-2017-9841/README.md POC Details
22 A PoC exploit for CVE-2017-9841 - PHPUnit Remote Code Execution(RCE) https://github.com/K3ysTr0K3R/CVE-2017-9841-EXPLOIT POC Details
23 "Argus" is a security tool designed to scan a list of websites for a known vulnerability in the PHPUnit framework, specifically the CVE-2017-9841 vulnerability. The tool attempts to exploit this vulnerability to verify its existence. https://github.com/joelindra/Argus POC Details
24 PHPUnit CVE-2017-9841 Scanner in Go clean and fire. https://github.com/drcrypterdotru/PHPUnit-GoScan POC Details
25 None https://github.com/Pwdnx1337/CVE-2017-9841 POC Details
26 🛡️ Scan for vulnerable PHPUnit endpoints quickly with this fast, multithreaded tool, ensuring your applications stay secure against CVE-2017-9841. https://github.com/Habibullah1101/PHPUnit-GoScan POC Details
27 Tool designed to scan a list of websites for a known vulnerability in the PHPUnit framework, specifically the CVE-2017-9841 vulnerability. https://github.com/joelindra/CVE-2017-9841 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-9841

登录查看更多情报信息。

Patches & Fixes for CVE-2017-9841 (2)

Vendor Advisories for CVE-2017-9841 (4)

Other References for CVE-2017-9841 (1)

Same Patch Batch · n/a · 2017-06-27 · 37 CVEs total

CVE-2015-7898 Samsung Galaxy S6 Samsung Gallery 安全漏洞
CVE-2015-1795 Red Hat Gluster 权限许可和访问控制问题漏洞
CVE-2015-2245 Huawei Ascend P7 拒绝服务漏洞
CVE-2015-3840 Android 安全漏洞
CVE-2015-5180 glibc 代码问题漏洞
CVE-2015-5378 Elasticsearch Logstash 安全漏洞
CVE-2015-7780 ZOHO ManageEngine Firewall Analyzer 路径遍历漏洞
CVE-2015-7781 ZOHO ManageEngine Firewall Analyzer 安全漏洞
CVE-2015-7895 Samsung Galaxy S6 Samsung Gallery 安全漏洞
CVE-2015-1778 OpenDaylight 安全漏洞
CVE-2015-8697 Debian stalin 安全漏洞
CVE-2016-0959 Adobe Flash Player 安全漏洞
CVE-2016-4383 HPE Helion Openstack Glance glance-manage db 安全漏洞
CVE-2016-5414 Red Hat FreeIPA 安全漏洞
CVE-2016-6342 elog 安全漏洞
CVE-2016-7062 Red Hat Storage Console和Storage Console Node 安全漏洞
CVE-2017-2491 Apple Safari和iOS JavaScriptCore 安全漏洞
CVE-2017-6086 Open Source Solutions ViMbAdmin 跨站请求伪造漏洞
CVE-2017-9256 Freeware Advanced Audio Decoder 2 安全漏洞
CVE-2017-9219 Freeware Advanced Audio Decoder 2 缓冲区错误漏洞

Showing top 20 of 37 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2017-9841

No comments yet


Leave a comment