Executive brief
The eval-stdin.php component in PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data starting with a '<?php ' substring. This occurs when the /vendor folder is exposed to external access, enabling command injection.
Affected products
- PHPUnit Project PHPUnit before 4.8.28, 5.x before 5.6.3
- Oracle Communications Diameter Signaling Router 8.0.0 - 8.5.0
Timeline
- 2017-06-24: disclosed: Initial CVE assignment date (implied by CVE ID)
- 2017-11-14: advisory: SecurityFocus BID 101798 published
- 2021-10-20: patched: Oracle released patches in Critical Patch Update
- 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-02-15: exploited: Confirmed exploited in the wild per CISA KEV catalog