• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

PHP7 bugs used by hackers to remotely hijack web servers

6112

Last week, Emil ‘Neex’ Lerner, a Russia-based security researcher, disclosed a remote code execution vulnerability in PHP 7, and this vulnerability has CVE-ID of 2019-11043, an attacker could force a remote webserver to execute their own arbitrary code simply by accessing a crafted URL. By just adding “?a=” to the website address, followed by their payload.

According to sources, this attack lessens the barriers to the threat actors to get an entry for hacking a website,which means even a non-technical person can orchestrate an attack.

The only good thing about this possible attack is that the vulnerability only impacts servers using the NGINX web server with the PHP-FPM extension. PHP-FPM is a souped-up version of FastCGI, with a few extra features designed for high-traffic websites.

While neither of those components is necessary to use PHP 7, they have an uncanny common factor, especially in commercial environments. Cimpanu points out that NextCloud, a large productivity software provider, uses PHP7 with NGINX and PHP-FPM.

It’s since released a security advisory to clients urging them to update warning them of the issue and imploring them to update their PHP install to the latest version.

Tags:
caden
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Tutorials in PHP7 bugs used by hackers to remotely hijack web servers

Related Tutorials in PHP7 bugs used by hackers to remotely hijack web servers

How to Upgrade and Downgrade the PHP Versions on CentOS 7.6
How to Upgrade and Downgrade the PHP Versions on CentOS 7.6
Jun 4, 2019
How to Configure Nginx as a Reverse Proxy in CentOS
How to Configure Nginx as a Reverse Proxy in CentOS
Nov 26, 2016
How to install Multiple PHP versions on CentOS 6
How to install Multiple PHP versions on CentOS 6
Nov 2, 2017
How To Create Python SimpleHTTPServer on ubuntu 18.04
How To Create Python SimpleHTTPServer on ubuntu 18.04
Jun 9, 2018
How to Configure Load Balancer in Apache
How to Configure Load Balancer in Apache
Nov 18, 2016
How to Install PHP 7.3v from Source Code on CentOS 7.6
How to Install PHP 7.3v from Source Code on CentOS 7.6
Jun 12, 2019
How to install Webmin in OpenSUSE
How to install Webmin in OpenSUSE
Nov 7, 2016
How to update PHP in Centos Web Panel
How to update PHP in Centos Web Panel
Feb 14, 2017

Related Forums in PHP7 bugs used by hackers to remotely hijack web servers

Related Forums in PHP7 bugs used by hackers to remotely hijack web servers

Web Server
jacob class=
How to remove httpd completely from server
Apr 7, 2017
Ubuntu
mason class=
"E: Package 'php-mcrypt' has no installation candidate" error on Ubuntu 20.4.1
Mar 15, 2021
Php
liam class=
The process /usr/local/bin/php artisan queue:work exceeded the timeout of 60 seconds
Jan 31, 2017
Nginx
levi class=
php files are downloading not executing in nginx
Apr 21, 2017
Web Server
wahab00727 class=
How to install Elastix PBX?
Dec 3, 2019
Php
stewart class=
Error: php70w-common conflicts with php-common-5.3.3-49.el6.x86_64
Sep 8, 2017
Apache
caden class=
how to use php variables in apache
May 12, 2017
CentOS
julian class=
Installation of php 5.6 on centos
Sep 19, 2017

Related News in PHP7 bugs used by hackers to remotely hijack web servers

Related News in PHP7 bugs used by hackers to remotely hijack web servers

PHP7 bugs used by hackers to remotely hijack web servers
PHP7 bugs used by hackers to remotely hijack web servers
Nov 5, 2019
WhatsApp and Telegram Security Flaw Can Make Hackers to Manipulate Media Files
WhatsApp and Telegram Security Flaw Can Make Hackers to Manipulate Media Files
Jul 19, 2019
EU Launches Bug Bounty for 15 Open Source Projects
EU Launches Bug Bounty for 15 Open Source Projects
Jan 14, 2019
OceanLotus Infused Cobalt Strike to BMW and Hyundai to Control the System
OceanLotus Infused Cobalt Strike to BMW and Hyundai to Control the System
Dec 11, 2019
Supermicro Servers with USBAnywhere Vulnerabilities Could Allow Hackers to Exploit Them Remotely
Supermicro Servers with USBAnywhere Vulnerabilities Could Allow Hackers to Exploit Them Remotely
Sep 11, 2019
Hackers exploit Mozilla Firefox bug reportedly affecting Coinbase users
Hackers exploit Mozilla Firefox bug reportedly affecting Coinbase users
Jun 26, 2019
Data typed on a laptop can be eavesdropped by hackers via smartphones
Data typed on a laptop can be eavesdropped by hackers via smartphones
Aug 27, 2019
Bugs in 4 OS and Safari browser patched by Apple
Bugs in 4 OS and Safari browser patched by Apple
Aug 1, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Sebastian ?
How to change non required to required field in SuiteCRM Custom/Default Modules

How to change not required to the required field in SuiteCRM Custom/Default Modules?

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.