
Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands.
A severe security flaw exists in PHP's CGI mode that allows attackers to run arbitrary commands by manipulating URL parameters.
Before running the script, ensure you have Python 3 installed on your system. Additionally, you need the requests library for handling HTTP requests.
You can install the required dependencies using pip. If pip is not installed, follow the instructions here.
requests library:pip install requests
To check a target URL for the CVE-2024-4577 vulnerability, follow these steps:
python3 exploit.py <target>
For instance, to test the URL http://example.com, run:
python3 exploit.py http://example.com
The script will test the provided target URL for the vulnerability and print the results to the console. It will indicate whether a potential vulnerability was found or if no vulnerability was detected.
(+) Potential vulnerability found at: http://example.com/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
(-) No vulnerability found at: http://example.com/php-cgi/php-cgi.exe?%ADd+allow_url_include
This vulnerability was found by Orange Tsai (@orange_8361)