CVE-2017-9841
KEVCRITICAL 9.8EPSS 100.0%
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-02-15
- Nuclei
- critical · CWE-94
- Published
- 2017-06-27
- Updated
- 2025-10-21
Proof-of-concept exploits (17)
- Chocapikk/CVE-2017-98417★ · 2026-01-16
- Jhonsonwannaa/CVE-2017-9841-1★ · 2025-03-02
- K3ysTr0K3R/CVE-2017-9841-EXPLOIT6★ · 2025-07-06
- MadExploits/PHPunit-Exploit5★ · 2023-02-04
- Mariam-kabu/cybersec-labs1★ · 2024-07-09
- MrG3P5/CVE-2017-98414★ · 2024-02-15
- akr3ch/CVE-2017-98413★ · 2022-08-19
- cyberharsh/Php-unit-CVE-2017-98410★ · 2020-06-24
- dream434/CVE-2017-98411★ · 2025-03-02
- dream434/CVE-2017-9841-1★ · 2025-03-02
- jax7sec/CVE-2017-98410★ · 2022-04-22
- marvinoon/P1BG3-ExploitScan0★ · 2025-02-28
- mbrasile/CVE-2017-98410★ · 2020-01-10
- mileticluka1/eval-stdin0★ · 2022-10-20
- moonwayy/hindicybersec1★ · 2024-07-09
- p1ckzi/CVE-2017-98413★ · 2022-06-30
- krisdewa/CVE-2017-9841-PHPUnit-Remote-Code-Execution-PoC
Nuclei templates (1)
ExploitDB entries (1)
Vulhub environments (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/phpunit-cve-2017-9841-rce.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2017/CVE-2017-9841.yaml