{"id":"CVE-2017-9841","vendor_project":"PHPUnit","product":"PHPUnit","vulnerability_name":"PHPUnit Command Injection Vulnerability","date_added":"2022-02-15","due_date":"2022-08-15","known_ransomware_use":"Unknown","short_description":"PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a \"<?php \" substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.","required_action":"Apply updates per vendor instructions.","cwes":"CWE-94","cvss_version":"3.1","cvss_severity":"CRITICAL","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","nvd_published":"2017-06-27","nvd_status":"Analyzed","epss":0.99999,"epss_percentile":0.99994,"cvss_score":9.8,"days_published_to_kev":1694,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2017-9841","by":"CyberMax"}