CVE record
CVE-2017-9841
PHPUnit Command Injection Vulnerability
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
critical
CVSS 9.8 ยท CVSS_V3
Affected packages
1
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- PHPUnit
- Product
- PHPUnit
- Date added
- Feb 15, 2022
- CISA federal remediation due date
- Aug 15, 2022
- Required action
- Apply updates per vendor instructions.
- Known ransomware campaign use
- Unknown
- CWE
- CWE-94
OSV package mapping
Affected open-source packages
| Package | Ecosystem | Fixed versions |
|---|---|---|
| phpunit/phpunit | composer | 4.8.28, 5.6.3 |