Web1 vuln-feed

Finding #114

Inventory item apache-test 2.4.37 (software, apache)
TitlePHPUnit PHPUnit: PHPUnit Command Injection Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:12Z
Last updated2026-06-11T07:35:12Z
Source advisoryPHPUnit PHPUnit: PHPUnit Command Injection Vulnerability
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

Update status