CVE-2024-4577: PHP CGI - Argument Injection

HoneyLabs honeypots recorded 9 probes matching CVE-2024-4577 from 7 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /php-cgi/php-cgi.exe

Addresses probing it

Source IPProbesNetworkCountry
34.89.245.2282Google LLCGermany
35.187.246.1472Google LLCSingapore
93.123.109.2141Techoff Srv LimitedBulgaria
172.71.124.2001Cloudflare, Inc.Singapore
136.90.15.1661Google LLCUnited States
34.84.217.481Google LLCJapan
136.90.54.1311Google LLCUnited States

Networks it comes from

ASNOrganisationProbesSource IPs
AS396982Google LLC75
AS13335Cloudflare, Inc.11
AS48090Techoff Srv Limited11

Captured requests

  • /php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
  • /php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input

CVE report

CVE report

Open a specific CVE from the CVE tracker.