PHP是一种在服务器端执行的脚本语言。 PHP存在操作系统命令注入漏洞,该漏洞源于在特定条件下,Windows系统使用“Best-Fit”行为替换命令行中的字符,这可能导致PHP CGI模块错误地将这些字符解释为PHP选项,从而泄露脚本的源代码,在服务器上运行任意PHP代码等。以下版本受到影响:8.1至8.1.29之前版本,8.3至8.3.8之前版本,8.2至8.2.20之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters. | https://github.com/TAM-K592/CVE-2024-4577 | POC Details |
| 2 | CVE-2024-4577 | https://github.com/ohhhh693/CVE-2024-4577 | POC Details |
| 3 | PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC | https://github.com/Junp0/CVE-2024-4577 | POC Details |
| 4 | None | https://github.com/princew88/CVE-2024-4577 | POC Details |
| 5 | POC & $BASH script for CVE-2024-4577 | https://github.com/11whoami99/CVE-2024-4577 | POC Details |
| 6 | PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC | https://github.com/watchtowrlabs/CVE-2024-4577 | POC Details |
| 7 | CVE-2024-4577 | https://github.com/zjhzjhhh/CVE-2024-4577 | POC Details |
| 8 | None | https://github.com/huseyinstif/CVE-2024-4577-Nuclei-Template | POC Details |
| 9 | None | https://github.com/taida957789/CVE-2024-4577 | POC Details |
| 10 | None | https://github.com/Wh02m1/CVE-2024-4577 | POC Details |
| 11 | Nuclei Template for CVE-2024-4577 | https://github.com/Sysc4ll3r/CVE-2024-4577 | POC Details |
| 12 | None | https://github.com/WanLiChangChengWanLiChang/CVE-2024-4577-RCE-EXP | POC Details |
| 13 | None | https://github.com/Yukiioz/CVE-2024-4577 | POC Details |
| 14 | CVE-2024-4577 nuclei-templates | https://github.com/0x20c/CVE-2024-4577-nuclei | POC Details |
| 15 | Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands. | https://github.com/manuelinfosec/CVE-2024-4577 | POC Details |
| 16 | CVE-2024-4577 Exploit POC | https://github.com/zomasec/CVE-2024-4577 | POC Details |
| 17 | PoC for CVE-2024-4577 written in bash, go, python and a nuclei template | https://github.com/ZephrFish/CVE-2024-4577-PoC | POC Details |
| 18 | PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template | https://github.com/ZephrFish/CVE-2024-4577-PHP-RCE | POC Details |
| 19 | [漏洞复现] 全球首款利用PHP默认环境的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP,共享原创EXP,支持SSRF,支持绕过WAF。The world's first CVE-2024-4577 PHP-CGI RCE exploit utilizing the default PHP environment. Sharing original exploit, supports SSRF, supports WAF bypass. | https://github.com/xcanwin/CVE-2024-4577-PHP-RCE | POC Details |
| 20 | python poc编写练手,可以对单个目标或批量检测 | https://github.com/dbyMelina/CVE-2024-4577 | POC Details |
| 21 | PHP CGI Argument Injection vulnerability | https://github.com/Chocapikk/CVE-2024-4577 | POC Details |
| 22 | A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE) | https://github.com/K3ysTr0K3R/CVE-2024-4577-EXPLOIT | POC Details |
| 23 | Bash script that checks if a PHP CGI setup is vulnerable to the CVE-2024-4577 argument injection vulnerability | https://github.com/it-t4mpan/check_cve_2024_4577.sh | POC Details |
| 24 | This is a PoC for PHP CVE-2024-4577. | https://github.com/bl4cksku11/CVE-2024-4577 | POC Details |
| 25 | php-cgi RCE快速检测 | https://github.com/nemu1k5ma/CVE-2024-4577 | POC Details |
| 26 | CVE-2024-4577 | https://github.com/aaddmin1122345/CVE-2024-4577-POC | POC Details |
| 27 | POC for CVE-2024-4577 with Shodan integration | https://github.com/d3ck4/Shodan-CVE-2024-4577 | POC Details |
| 28 | None | https://github.com/Entropt/CVE-2024-4577_Analysis | POC Details |
| 29 | None | https://github.com/XiangDongCJC/CVE-2024-4577-PHP-CGI-RCE | POC Details |
| 30 | None | https://github.com/hexedbyte/cve-2024-4577 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-5585 | 7.7 HIGH | Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fi |
| CVE-2024-5458 | 5.3 MEDIUM | Filter bypass in filter_var (FILTER_VALIDATE_URL) |
| CVE-2024-2408 | PHP is vulnerable to the Marvin Attack |
No comments yet