by @jakaba
18 Jun 2024

PHP CGI argument injection to RCE (CVE-2024-4577)

by @jakaba
18 Jun 2024

PHP CGI argument injection to RCE (CVE-2024-4577)

CVEs

9.8 Critical Severity

Apps

PHP
PHPPHP
8.1.27.*
8.1.27.-
8.1.27.RC1
7.4.33-10.*
8.1.1910.*
8.1.29.-
8.1.29.RC1
8.1.26.RC1
8.1.26.-
7.4.3340.*

Screenshots from the blog posts

images/clxkhh7scp8ox1hok7plb84d6.jpgimages/clxkhh7scp8ox1hok7plb84d6.jpg

Summary

CVE-2024-4577 is a critical PHP CGI vulnerability allowing remote code execution via argument injection. It affects servers in specific locales on Windows, bypassing previous protections.

Description

users/photos/clj8b3h1k16g10uoihwvzgsxi.png

@jakaba

74 posts

Total vcoins

64.3K

Social media links

Comments (0)