CVE-2024-4577
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
- Php
- < 8.1.29, 8.2.20, 8.3.8
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2024-06-09
CVE-2024-4577 at NVD
100 known exploits for CVE-2024-4577
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2024-4577-Nuclei-Template
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577-RCE
CVE-2024-4577
CVE-2024-4577
cve-2024-4577
CVE-2024-4577-RCE
Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577-
php-cgi-cve-2024-4577
cve-2024-4577-lab
PHPCGIScanner
CVE-2024-4577-EXPLOIT
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577_PowerShell
CVE-2024-4577-Exploit
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577-checker
CVE-2024-4577_Analysis
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577-PHP-RCE
PHP-CGI-RCE-Scanner
CVE-2024-4577
CVE-2024-4577
php-cgi-Injector
cve-2024-4577-phpcgi_rce_reproduction
CVE-2024-4577-LetsDefend-walkthrough
CVE-2024-4577-RCE-ATTACK
CVE-2024-4577
CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation
cve-2024-4577
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577-PHP-RCE
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577
cve-2024-4577-lab
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577-rayng
CVE-2024-4577
CVE-2024-4577-RCE-EXP
MassExploit-CVE-2024-4577
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577-RCE-PoC
CVE-2024-4577
CVE-2024-4577
CVE-2024-4577-PHP-CGI-RCE
CVE-2024-4577-PHP-CGI-argument-injection-RCE
CVE-2024-4577
CVE-2024-4577
Shodan-CVE-2024-4577
CVE-2024-4577
ctf-cve-2024-4577
CVE-2024-4577-nuclei
PHP-CGI-INTERNAL-RCE
CVE-2024-4577-PHP-RCE
CVE-2024-4577
Exploit for OS Command Injection in Php
CVE-2024-4577-PHP-RCE
HTSOC
CVE-Web-Framework
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
📄 PHP CGI Remote Code Execution
PHP CGI Module 8.3.4 - Remote Code Execution (RCE)
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php
Exploit for OS Command Injection in Php