WeSearch

Year-Old PHP Vulnerability Is One of the Most Targeted Vulnerabilities

·9 min read · 0 reactions · 0 comments · 12 views
#cybersecurity#vulnerability#phpunit
Year-Old PHP Vulnerability Is One of the Most Targeted Vulnerabilities
⚡ TL;DR · AI summary

CVE-2017-9841, a critical remote code execution vulnerability in PHPUnit, remains one of the most targeted vulnerabilities nearly six years after its disclosure. Recent data shows over 80,000 exploitation attempts in just 30 days, indicating a sustained campaign by attackers. The vulnerability arises from a testing utility that was inadvertently left accessible in production environments, allowing for easy exploitation.

Key facts
Original article
VulnCheck
Read full at VulnCheck →
Opening excerpt (first ~120 words) tap to expand

CVE: CVE-2017-9841 | CVSS: 9.8 Critical | EPSS: 94.2% (99.9th percentile)Some vulnerabilities get patched, forgotten, and fade into the historical record. CVE-2017-9841 is not one of them.Nearly a decade after PHPUnit's eval-stdin.php file was identified as a trivially exploitable remote code execution vector, VulnCheck Canary data shows the vulnerability is one of the most actively targeted in our systems, with over 80,000 exploitation attempts detected in the last 30 days across our global Canaries network, and more than 36,500 hits in just the last 10 days. Attackers haven't moved on.

Excerpt limited to ~120 words for fair-use compliance. The full article is at VulnCheck.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from VulnCheck