目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-4577— PHP 操作系统命令注入漏洞

一分钟漏洞结论

影响对象
PHP Group PHP
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

PHP是一种在服务器端执行的脚本语言。 PHP存在操作系统命令注入漏洞,该漏洞源于在特定条件下,Windows系统使用“Best-Fit”行为替换命令行中的字符,这可能导致PHP CGI模块错误地将这些字符解释为PHP选项,从而泄露脚本的源代码,在服务器上运行任意PHP代码等。以下版本受到影响:8.1至8.1.29之前版本,8.3至8.3.8之前版本,8.2至8.2.20之前版本。

CVSS 9.8 · Critical KEV · 勒索软件 EPSS 99.99% · P100
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-4577 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Argument Injection in PHP-CGI
来源: CVE Program / CVE List V5
Vulnerability Description
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
来源: CVE Program / CVE List V5
Vulnerability Title
PHP 操作系统命令注入漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
PHP是一种在服务器端执行的脚本语言。 PHP存在操作系统命令注入漏洞,该漏洞源于在特定条件下,Windows系统使用“Best-Fit”行为替换命令行中的字符,这可能导致PHP CGI模块错误地将这些字符解释为PHP选项,从而泄露脚本的源代码,在服务器上运行任意PHP代码等。以下版本受到影响:8.1至8.1.29之前版本,8.3至8.3.8之前版本,8.2至8.2.20之前版本。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
PHP Group PHP 8.1.* ~ 8.1.29 -

二、漏洞 CVE-2024-4577 的公开POC

# POC 描述 源链接 神龙链接
1 CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters. https://github.com/TAM-K592/CVE-2024-4577 POC详情
2 CVE-2024-4577 https://github.com/ohhhh693/CVE-2024-4577 POC详情
3 PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC https://github.com/Junp0/CVE-2024-4577 POC详情
4 None https://github.com/princew88/CVE-2024-4577 POC详情
5 POC & $BASH script for CVE-2024-4577 https://github.com/11whoami99/CVE-2024-4577 POC详情
6 PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC https://github.com/watchtowrlabs/CVE-2024-4577 POC详情
7 CVE-2024-4577 https://github.com/zjhzjhhh/CVE-2024-4577 POC详情
8 None https://github.com/huseyinstif/CVE-2024-4577-Nuclei-Template POC详情
9 None https://github.com/taida957789/CVE-2024-4577 POC详情
10 None https://github.com/Wh02m1/CVE-2024-4577 POC详情
11 Nuclei Template for CVE-2024-4577 https://github.com/Sysc4ll3r/CVE-2024-4577 POC详情
12 None https://github.com/WanLiChangChengWanLiChang/CVE-2024-4577-RCE-EXP POC详情
13 None https://github.com/Yukiioz/CVE-2024-4577 POC详情
14 CVE-2024-4577 nuclei-templates https://github.com/0x20c/CVE-2024-4577-nuclei POC详情
15 Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands. https://github.com/manuelinfosec/CVE-2024-4577 POC详情
16 CVE-2024-4577 Exploit POC https://github.com/zomasec/CVE-2024-4577 POC详情
17 PoC for CVE-2024-4577 written in bash, go, python and a nuclei template https://github.com/ZephrFish/CVE-2024-4577-PoC POC详情
18 PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template https://github.com/ZephrFish/CVE-2024-4577-PHP-RCE POC详情
19 [漏洞复现] 全球首款利用PHP默认环境的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP,共享原创EXP,支持SSRF,支持绕过WAF。The world's first CVE-2024-4577 PHP-CGI RCE exploit utilizing the default PHP environment. Sharing original exploit, supports SSRF, supports WAF bypass. https://github.com/xcanwin/CVE-2024-4577-PHP-RCE POC详情
20 python poc编写练手,可以对单个目标或批量检测 https://github.com/dbyMelina/CVE-2024-4577 POC详情
21 PHP CGI Argument Injection vulnerability https://github.com/Chocapikk/CVE-2024-4577 POC详情
22 A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE) https://github.com/K3ysTr0K3R/CVE-2024-4577-EXPLOIT POC详情
23 Bash script that checks if a PHP CGI setup is vulnerable to the CVE-2024-4577 argument injection vulnerability https://github.com/it-t4mpan/check_cve_2024_4577.sh POC详情
24 This is a PoC for PHP CVE-2024-4577. https://github.com/bl4cksku11/CVE-2024-4577 POC详情
25 php-cgi RCE快速检测 https://github.com/nemu1k5ma/CVE-2024-4577 POC详情
26 CVE-2024-4577 https://github.com/aaddmin1122345/CVE-2024-4577-POC POC详情
27 POC for CVE-2024-4577 with Shodan integration https://github.com/d3ck4/Shodan-CVE-2024-4577 POC详情
28 None https://github.com/Entropt/CVE-2024-4577_Analysis POC详情
29 None https://github.com/XiangDongCJC/CVE-2024-4577-PHP-CGI-RCE POC详情
30 None https://github.com/hexedbyte/cve-2024-4577 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-4577 的情报信息

请登录查看更多情报信息。

CVE-2024-4577 补丁与修复 (1)

CVE-2024-4577 厂商安全公告 (2)

CVE-2024-4577 邮件列表归档 (3)

CVE-2024-4577 安全博客文章 (2)

CVE-2024-4577 新闻报道 (1)

CVE-2024-4577 其他参考 (9)

同批安全公告 · PHP Group · 2024-06-09 · 共 4 条

CVE-2024-5585 7.7 HIGH PHP 安全漏洞
CVE-2024-5458 5.3 MEDIUM PHP 安全漏洞
CVE-2024-2408 PHP 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2024-4577

暂无评论


发表评论