Record summary

CVE-2025-34061 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. The backdoor listens for base64-encoded PHP payloads in the Accept-Charset HTTP header of incoming requests, decodes and executes the payload without proper validation. This leads to remote code execution as the web server user, compromising the affected system.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 7, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List2016 to ≤ 2018affected

Proofs of concept

1

Catalogued exploits

MetasploitPHPStudy Backdoor Remote Code executionMetasploit exploitby Airevan +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

3