vendor:
PHP
by:
flast101
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: PHP
Affected Version From: 8.1.0-dev
Affected Version To: 8.1.0-dev
Patch Exists: NO
Related CWE:
CPE: php:php:8.1.0-dev
Platforms Tested: Ubuntu 20.04
2021
PHP 8.1.0-dev – ‘User-Agentt’ Remote Code Execution
An early release of PHP, the PHP 8.1.0-dev version was released with a backdoor on March 28th 2021, but the backdoor was quickly discovered and removed. If this version of PHP runs on a server, an attacker can execute arbitrary code by sending the User-Agentt header. The following exploit uses the backdoor to provide a pseudo shell on the host.
Mitigation:
Upgrade to a patched version of PHP and remove any unauthorized or suspicious code from the server.