References https://www.cnblogs.com/mrhonest/p/10892641.html https://zhuanlan.zhihu.com/p/24955090 https://security.alpinelinux.org/vuln/CVE-2017-5340 https://ubuntu.com/security/CVE-2017-5340 https://cve.circl.lu/cve/CVE-2017-5340 https://bugs.php.net/bug.php?id=73832 https://github.com/php/php-src/commit/4cc0286f2f3780abc6084bcdae5dce595daa3c12
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-48611: phpBB < 3.3.17 - Authentication BypassPoCCVE-2026-46364: phpMyFAQ <= 4.1.1 - SQL InjectionPoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionphpVMS /importer 未授权访问漏洞(CVE-2026-42569)PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSphpMyFAQ /api/captcha SQL 注入漏洞PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassphpVMS存在权限绕过漏洞(CVE-2026-42569)PoCCVE-2020-26935: phpMyAdmin < 5.0.3 - SQL InjectionPoCphp-prober-exposure: PHP Prober - ExposurePoCcakephp-debugkit-exposure: CakePHP - Debug Kit Toolbar ExposurePoCCVE-2025-69200: phpMyFAQ - Configuration Backup Disclosure