Web Hack List

Collected research

CVE-2024-4577 - Yet Another PHP RCE: Make PHP-CGI Argument Injection Great Again!

A short note on CVE-2024-4577 published alongside the official PHP advisory, written while the author prepared his Black Hat Apache talk. It reports that the php-cgi argument-injection patch reviewed and trusted for twelve years is bypassed by a minor Windows character-conversion feature, letting unauthenticated attackers run arbitrary code through particular character sequences; XAMPP for Windows is affected in its default configuration.

Record

Researcher
Orange Tsai
Published by
DEVCORE
Date
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Orange Tsai, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .