PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)# CVE-2024-4577 Exploit
Exploit of the PHP CGI Argument Injection vulnerability (CVE-2024-4577) to achieve Remote Code Execution (RCE) on a vulnerable PHP version running in a Windows environment, discovered by [Orange Tsai](https://x.com/orange_8361). For more details, check out [DEVCORE's Blog](https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/).
## Requirements
Language Used = Python3<br />
Modules/Packages used:
* random
* string
* requests
* warnings
* datetime
* optparse
* colorama
* multiprocessing
* time
<!-- -->
Install the dependencies:
```bash
pip install -r requirements.txt
```
[4.0K] /data/pocs/4079d1687dde5c515b98b744564dd8be15aea0f9
├── [4.1K] main.py
├── [ 652] README.md
└── [ 26] requirements.txt
0 directories, 3 files