Collected research
CVE-2024-4577 - Yet Another PHP RCE: Make PHP-CGI Argument Injection Great Again!
A short note on CVE-2024-4577 published alongside the official PHP advisory, written while the author prepared his Black Hat Apache talk. It reports that the php-cgi argument-injection patch reviewed and trusted for twelve years is bypassed by a minor Windows character-conversion feature, letting unauthenticated attackers run arbitrary code through particular character sequences; XAMPP for Windows is affected in its default configuration.
Record
- Researcher
- Orange Tsai
- Published by
- DEVCORE
- Date
- Topic
- Injection
In the archive
Related sources
- Official PHP security advisory Advisory
Tags
This page is the archive's own catalogue record. The research is the work of Orange Tsai, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .