PHP code could be easily exploited to let hackers target Windows servers


Source: techradar.com techradar.com

Key Topics in this News Article:

News Snapshot:

Cybersecurity researchers have discovered a new vulnerability in PHP which could allow hackers to run malicious code remotely. The vulnerability is tracked as CVE-2’24-4577, and is described as a CGI argument injection vulnerability. At press time, it did not have a severity score assigned, but we do know that it affects all versions of PHP installed on the Windows operating system, and it was introduced when the team tried to patch a different flaw. As the researchers from DEVCORE explained, the vulnerability was introduced when patching CVE-2012-1823: "While implementing PHP, the team did not notice the Best-Fit feature of encoding...