CVE-2017-9841

CRITICAL KEV NUCLEI

PHPUnit <4.8.28, <5.6.3 - RCE

Title source: llm

Description

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

Exploits (21)

nomisec SCANNER 29 stars
by RandomRobbieBF · remote
https://github.com/RandomRobbieBF/phpunit-brute
nomisec SCANNER 23 stars
by incogbyte · remote
https://github.com/incogbyte/laravel-phpunit-rce-masscaner
nomisec WORKING POC 7 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2017-9841
nomisec SCANNER 6 stars
by ludy-dev · remote
https://github.com/ludy-dev/PHPUnit_eval-stdin_RCE
nomisec WORKING POC 5 stars
by MadExploits · poc
https://github.com/MadExploits/PHPunit-Exploit
nomisec WORKING POC 4 stars
by K3ysTr0K3R · poc
https://github.com/K3ysTr0K3R/CVE-2017-9841-EXPLOIT
nomisec SCANNER 4 stars
by MrG3P5 · remote
https://github.com/MrG3P5/CVE-2017-9841
nomisec SCANNER 4 stars
by drcrypterdotru · remote
https://github.com/drcrypterdotru/PHPUnit-GoScan
nomisec WORKING POC 3 stars
by akr3ch · remote
https://github.com/akr3ch/CVE-2017-9841
nomisec WORKING POC 3 stars
by p1ckzi · remote
https://github.com/p1ckzi/CVE-2017-9841
nomisec WORKING POC 1 stars
by dream434 · remote
https://github.com/dream434/CVE-2017-9841
nomisec SCANNER
by joelindra · poc
https://github.com/joelindra/CVE-2017-9841
nomisec WORKING POC
by mileticluka1 · remote
https://github.com/mileticluka1/eval-stdin
nomisec WORKING POC
by jax7sec · remote
https://github.com/jax7sec/CVE-2017-9841
nomisec WRITEUP
by cyberharsh · poc
https://github.com/cyberharsh/Php-unit-CVE-2017-9841
nomisec WRITEUP
by MR-LeonardoGomes · poc
https://github.com/MR-LeonardoGomes/CVE-2017-9841
gitlab SCANNER
by drygdryg · poc
https://gitlab.com/drygdryg/phpunit-brute
nomisec SCANNER
by mbrasile · poc
https://github.com/mbrasile/CVE-2017-9841
vulncheck_xdb SCANNER
remote
https://github.com/joelindra/Argus
exploitdb WORKING POC
by souzo · pythonwebappsphp
https://www.exploit-db.com/exploits/50702

Nuclei Templates (1)

PHPUnit - Remote Code Execution
CRITICALby Random_Robbie,pikpikcu

Scores

CVSS v3 9.8
EPSS 0.9421
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-02-15
VulnCheck KEV 2020-11-22
InTheWild.io 2021-04-08
ENISA EUVD EUVD-2022-1528

Classification

CWE
CWE-94
Status draft

Affected Products (3)

phpunit_project/phpunit < 4.8.27
oracle/communications_diameter_signaling_router < 8.5.0
phpunit/phpunit < 4.8.28Packagist

Timeline

Published Jun 27, 2017
KEV Added Feb 15, 2022
Tracked Since Feb 18, 2026