Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-9841

Опубликовано: 27 июн. 2017
Источник: ubuntu
Приоритет: high
EPSS Критический
CVSS2: 7.5
CVSS3: 9.8

Описание

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

6.5.5-1ubuntu2
cosmic

not-affected

6.5.5-1ubuntu2
devel

not-affected

6.5.5-1ubuntu2
disco

not-affected

6.5.5-1ubuntu2
eoan

not-affected

6.5.5-1ubuntu2
esm-apps/bionic

not-affected

6.5.5-1ubuntu2
esm-apps/focal

not-affected

6.5.5-1ubuntu2
esm-apps/jammy

not-affected

6.5.5-1ubuntu2
esm-apps/noble

not-affected

6.5.5-1ubuntu2

Показывать по

EPSS

Процентиль: 100%
0.94202
Критический

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

CVSS3: 9.8
debian
больше 8 лет назад

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 ...

CVSS3: 9.8
github
почти 4 года назад

Code Injection in PHPUnit

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость компонента Util/PHP/eval-stdin.php фреймворка PHPUnit, позволяющая нарушителю выполнить произвольный PHP-код

EPSS

Процентиль: 100%
0.94202
Критический

7.5 High

CVSS2

9.8 Critical

CVSS3