CVE-2017-9841

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
27/06/2017
Last modified:
20/04/2025

Description

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:*:*:* 4.8.27 (including)
cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:*:*:* 5.0.0 (including) 5.6.3 (excluding)
cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:* 8.0.0 (including) 8.5.0 (including)