Junglewise Threat Intelligence

CVE-2017-9841: PHPUnit Command Injection Vulnerability

CVE-2017-9841 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-02-15

Vendors: Oracle.

Executive brief

The eval-stdin.php component in PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data starting with a '<?php ' substring. This occurs when the /vendor folder is exposed to external access, enabling command injection.

Affected products

  • PHPUnit Project PHPUnit before 4.8.28, 5.x before 5.6.3
  • Oracle Communications Diameter Signaling Router 8.0.0 - 8.5.0

Timeline

  • 2017-06-24: disclosed: Initial CVE assignment date (implied by CVE ID)
  • 2017-11-14: advisory: SecurityFocus BID 101798 published
  • 2021-10-20: patched: Oracle released patches in Critical Patch Update
  • 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-15: exploited: Confirmed exploited in the wild per CISA KEV catalog