References https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability/ https://www.akamai.com/zh/blog/security-research/2024-php-exploit-cve-one-day-after-disclosure https://zhuanlan.zhihu.com/p/707184342 https://kizureina.github.io/2024/06/08/Analysis-of-CVE-2024-4577/ https://cloud.tencent.com/developer/article/2426933 https://rivers.chaitin.cn/blog/cq957f90lnechd244v10 https://www.xsssql.com/article/876.html https://comate.baidu.com/zh/page/s62nyivjdua https://xlab.csdn.net/681030fde47cbf761b635774.html https://www.cnblogs.com/phpphp/p/18859709 https://cve.imfht.com/poc_detail/6641afe5e644a893d4f5bd87cae735db76938a18 https://cn-sec.com/archives/2852164.html https://nobb.site/2024/07/11/0x8C/ https://forum.gamer.com.tw/C.php?bsn=60030&snA=646370 https://www.hgiga.com/prewarning.html https://github.com/watchtowrlabs/CVE-2024-4577 https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2024-4577 https://www.tenable.com/plugins/nessus/200464 https://community.fortinet.com/blogs-103/fortiweb-security-insights-addressing-cve-2024-4577-php-cgi-argument-injection-vulnerability-185568 https://learn.microsoft.com/en-us/answers/questions/1725847/php-8-3-vulnerability-cve-2024-4577 https://www.broadcom.com/support/security-center/protection-bulletin/protection-highlight-cve-2024-4577-php-cgi-argument-injection-vulnerability https://www.herodevs.com/blog-posts/cve-2024-4577-highlights-a-critical-vulnerability-in-php https://cert.tanet.edu.tw/prog/opendoc.php?id=2025010801015757363564577204841.pdf
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-48611: phpBB < 3.3.17 - Authentication BypassPoCCVE-2026-46364: phpMyFAQ <= 4.1.1 - SQL InjectionPoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionphpVMS /importer 未授权访问漏洞(CVE-2026-42569)PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSphpMyFAQ /api/captcha SQL 注入漏洞PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassphpVMS存在权限绕过漏洞(CVE-2026-42569)PoCCVE-2020-26935: phpMyAdmin < 5.0.3 - SQL InjectionPoCphp-prober-exposure: PHP Prober - ExposurePoCcakephp-debugkit-exposure: CakePHP - Debug Kit Toolbar ExposurePoCCVE-2025-69200: phpMyFAQ - Configuration Backup Disclosure