Web1 vuln-feed

Finding #27

Inventory item php-test 8.3.31 (software, php)
TitlePHPUnit PHPUnit: PHPUnit Command Injection Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:11Z
Last updated2026-06-11T07:35:11Z
Source advisoryPHPUnit PHPUnit: PHPUnit Command Injection Vulnerability
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

Update status