Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-11043— Underflow in PHP-FPM can lead to RCE

CVSS 8.7 · High KEV · Ransomware EPSS 94.05% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-11043

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Underflow in PHP-FPM can lead to RCE
Source: NVD (National Vulnerability Database)
Vulnerability Description
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: NVD (National Vulnerability Database)
Vulnerability Title
PHP 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHPGroup和开放源代码社区的共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 PHP中存在缓冲区错误漏洞。该漏洞源于网络系统或产品在内存上执行操作时,未正确验证数据边界,导致向关联的其他内存位置上执行了错误的读写操作。攻击者可利用该漏洞导致缓冲区溢出或堆溢出等。以下产品及版本受到影响:PHP 7.1.33之前版本的7.1.x版本,7.2.24之前版本的7.2.x版本,7
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
PHPPHP 7.1.x ~ 7.1.33 -

II. Public POCs for CVE-2019-11043

#POC DescriptionSource LinkShenlong Link
1Exploit for CVE-2019-11043https://github.com/neex/phuip-fpizdamPOC Details
2CVE-2019-11043https://github.com/B1gd0g/CVE-2019-11043POC Details
3Nonehttps://github.com/tinker-li/CVE-2019-11043POC Details
4php-fpm+Nginx RCEhttps://github.com/jas502n/CVE-2019-11043POC Details
5PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Pythonhttps://github.com/AleWong/PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043-POC Details
6Nonehttps://github.com/ianxtianxt/CVE-2019-11043POC Details
7Nonehttps://github.com/fairyming/CVE-2019-11043POC Details
8Nonehttps://github.com/akamajoris/CVE-2019-11043-DockerPOC Details
9(PoC) Python version of CVE-2019-11043 exploit by neexhttps://github.com/theMiddleBlue/CVE-2019-11043POC Details
10CVE-2019-11043 PHP远程代码执行https://github.com/shadow-horse/cve-2019-11043POC Details
11Python exp for CVE-2019-11043https://github.com/huowen/CVE-2019-11043POC Details
12Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.https://github.com/ypereirareis/docker-CVE-2019-11043POC Details
13CVE-2019-11043 && PHP7.x && RCE EXPhttps://github.com/MRdoulestar/CVE-2019-11043POC Details
14CVE-2019-11043 PHP7.x RCEhttps://github.com/0th3rs-Security-Team/CVE-2019-11043POC Details
15Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)https://github.com/k8gege/CVE-2019-11043POC Details
16remote debug environment for CLionhttps://github.com/moniik/CVE-2019-11043_envPOC Details
17This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.https://github.com/kriskhub/CVE-2019-11043POC Details
18Nonehttps://github.com/alokaranasinghe/cve-2019-11043POC Details
19quick and dirty PHP RCE proof of concepthttps://github.com/corifeo/CVE-2019-11043POC Details
20PHP-FPM Remote Command Execution Exploithttps://github.com/lindemer/CVE-2019-11043POC Details
21CVE-2019-11043https://github.com/jptr218/php_hackPOC Details
22CVE-2019-11043 LABhttps://github.com/jas9reet/CVE-2019-11043POC Details
23Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E8%AF%AD%E8%A8%80%E6%BC%8F%E6%B4%9E/PHP-FPM%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2019-11043.mdPOC Details
24https://github.com/vulhub/vulhub/blob/master/php/CVE-2019-11043/README.mdPOC Details
25exploit for CVE-2019-11043 https://github.com/bayazid-bit/CVE-2019-11043-POC Details
26Nonehttps://github.com/a1ex-var1amov/ctf-cve-2019-11043POC Details
27Exploit for CVE-2019-11043https://github.com/CodeHex083/phuip-fpizdamPOC Details
28Nonehttps://github.com/AndrewMas99/CVE-2019-11043-VulnerabilityPOC Details
29Python port of an ExploitDB proof-of-concept.https://github.com/gon905332-jpg/cve-2019-11043.pyPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-11043

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2019-11043

No comments yet


Leave a comment