Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade phpunit | Jul 30, 2024 | Jun 27, 2017 |
| Freebsd | — | Upgrade mediawiki129Upgrade mediawiki128Upgrade mediawiki127 | Nov 19, 2017 | Nov 19, 2017 |
| Gentoo Linux | — | Upgrade dev-php/phpunit. | Nov 20, 2017 | Jun 27, 2017 |
| Moodle | — | Upgrade to the latest version of Moodle | Sep 19, 2017 | Jun 27, 2017 |
| Ubuntu | — | Upgrade phpunit (Ubuntu Pro) | Dec 19, 2024 | Jun 27, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub