ニュース

CVE-2024-4577 affects PHP only when it runs in a mode known as CGI, in which a web server parses HTTP requests and passes them to a PHP script for processing. Even when PHP isn’t set to CGI mode ...
The actors create a basic backdoor using a debugging function that allows the system to download two webshells onto the US firm's web server, giving the attackers backdoors for further exploitation.