CVE-2024-4577: PHP CGI - Argument Injection
HoneyLabs honeypots recorded 9 probes matching CVE-2024-4577 from 7 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /php-cgi/php-cgi.exe
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 34.89.245.228 | 2 | Google LLC | Germany |
| 35.187.246.147 | 2 | Google LLC | Singapore |
| 93.123.109.214 | 1 | Techoff Srv Limited | Bulgaria |
| 172.71.124.200 | 1 | Cloudflare, Inc. | Singapore |
| 136.90.15.166 | 1 | Google LLC | United States |
| 34.84.217.48 | 1 | Google LLC | Japan |
| 136.90.54.131 | 1 | Google LLC | United States |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS396982 | Google LLC | 7 | 5 |
| AS13335 | Cloudflare, Inc. | 1 | 1 |
| AS48090 | Techoff Srv Limited | 1 | 1 |
Captured requests
- /php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
- /php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
CVE report
CVE report
Open a specific CVE from the CVE tracker.