You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
smalyshev
published
GHSA-9fcc-425m-g385Jun 9, 2024
Package
No package listed
Affected versions
8.3.6
Patched versions
8.1.29, 8.2.20, 8.3.8
Description
Summary
same as CVE-2024-1874
due to the improper handling of command line arguments on Windows, maliciously crafted arguments can inject arbitrary commands even if the bypass_shell option is enabled.
Details
Add a space at the end of filename, others are the same as CVE-2024-1874
PoC
Save the following file as test.bat
echo hello
Save the following file as 1.php, notiece the space at the end of argv-filename
Summary
same as CVE-2024-1874
Details
Add a space at the end of filename, others are the same as CVE-2024-1874
PoC
Impact
Malicious command line arguments in windows platform