References https://www.mycert.org.my/portal/advisory?id=MA-756.102019 https://www.anquanke.com/post/id/189415 https://blog.orange.tw/posts/2019-10-an-analysis-and-thought-about-recently/ https://www.secpod.com/blog/php-rce-exploited-in-the-wild-cve-2019-11043 https://cloud.tencent.com/developer/article/1536640 https://hackerone.com/reports/722327 https://www.tenablecloud.cn/plugins/nessus/136744 https://www.svenbeast.com/post/dyp738nRt/ https://bugs.php.net/78599 https://nsfocusglobal.com/php-fpm-remote-code-execution-vulnerability-cve-2019-11043-threat-alert/ https://www.dptech.com/index.php?m=content&c=index&a=show&catid=1695&id=1845 https://developer.jdcloud.com/article/767 https://www.tenable.com/blog/cve-2019-11043-vulnerability-in-php-fpm-could-lead-to-remote-code-execution-on-nginx https://www.nsfocus.com.cn/html/2019/39_1025/829.html https://blog.detectify.com/product-updates/cve-2019-11043-nginx-php-fpm-exploit/ https://nvd.nist.gov/vuln/detail/CVE-2019-11043 https://bugs.php.net/bug.php?id=78599
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-48611: phpBB < 3.3.17 - Authentication BypassPoCCVE-2026-46364: phpMyFAQ <= 4.1.1 - SQL InjectionPoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionphpVMS /importer 未授权访问漏洞(CVE-2026-42569)PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSphpMyFAQ /api/captcha SQL 注入漏洞PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassphpVMS存在权限绕过漏洞(CVE-2026-42569)PoCCVE-2020-26935: phpMyAdmin < 5.0.3 - SQL InjectionPoCphp-prober-exposure: PHP Prober - ExposurePoCcakephp-debugkit-exposure: CakePHP - Debug Kit Toolbar ExposurePoCCVE-2025-69200: phpMyFAQ - Configuration Backup Disclosure