Skip to content

feature: php-cgi - CVE-2024-4577 - remote code execution #132

@hyde-repo

Description

@hyde-repo

Add CVE‑2024‑4577 to the inventory.

A critical argument injection flaw in PHP‑CGI on Windows allows unauthenticated attackers using specific locales (e.g. Chinese, Japanese) to pass crafted characters (e.g. soft hyphen 0xAD) that are misinterpreted as PHP CLI options, enabling remote code execution.

Section: ctf/web/php-cgi/
Type: argument injection / remote code execution

Windows only ?

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions