Finding #114
| Inventory item | apache-test 2.4.37 (software, apache) |
|---|---|
| Title | PHPUnit PHPUnit: PHPUnit Command Injection Vulnerability |
| Match | keyword / confidence low |
| Status | new |
| First seen | 2026-06-11T07:35:12Z |
| Last updated | 2026-06-11T07:35:12Z |
| Source advisory | PHPUnit PHPUnit: PHPUnit Command Injection Vulnerability PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI. |