
Docker-based lab to reproduce CVE-2017-9841, a remote code execution vulnerability in PHPUnit's eval-stdin.php when installed under a web root.
Composer is a PHP package management tool. Using Composer to install extension packages will create a vendor folder in the current directory and place all files in it. Usually this directory should be placed outside the web root so that users cannot directly access it.
PHPUnit is a unit testing tool in PHP. In versions 4.8.19 ~ 4.8.27 and 5.0.10 ~ 5.6.2, the file vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php contains the following code:
eval('?>'.file_get_contents('php://input'));
If this file is directly accessed by a user, it will lead to a remote code execution vulnerability.
Reference link: http://phpunit.vulnbusters.com
Execute the following command to start a PHP environment, where PHPUnit is installed in the web directory.
docker-compose build
docker-compose up -d
The web environment will start at http://your-ip:8080.
Directly send PHP code as the POST body to http://your-ip:8080/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php:
