Vulnerability threat dossier

CVE-2017-9841

oraclecommunications diameter signaling router

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

VTP deterministic threat50.0of 100 · CVSS excluded

VTP analyst assessment

PHPUnit remote PHP code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factKEV

Assessment

CVE-2017-9841 allows remote PHP code execution when a vulnerable PHPUnit eval-stdin endpoint is exposed. CISA KEV lists it as known to be exploited globally. The supplied exploit-source record does not describe this CVE, so it adds no useful exploit detail.

Why it matters

  • Successful exploitation can let an unauthenticated attacker run PHP code.
  • The affected endpoint is reachable when the PHPUnit vendor path is exposed to the web.

Evidence

1 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

No first-party telemetry is configured, so VTP observation is unknown.

The supplied exploit-source record is unrelated to this CVE.

CISA KEV confirms known global exploitation, not activity in a specific environment.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

Review in your environment: if you use PHPUnit, check whether the eval-stdin.php path is externally reachable under a vendor directory.

AI baseline history (1)
  1. BASELINE ASSESSED
    PHPUnit remote PHP code executiongpt-5.6-terra · low
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
HIGH

Honeypot request semantics are strongly consistent with CVE-2017-9841. This identifies likely attack intent, not successful exploitation or execution.

STRONGLY COMPATIBLETechnical consistency 95/100

Basis: deterministic technical candidate

Strongly consistent attempt; successful exploitation not observedDisclosure embargo completed
HIGH

Honeypot request semantics are strongly consistent with CVE-2017-9841. This identifies likely attack intent, not successful exploitation or execution.

STRONGLY COMPATIBLETechnical consistency 95/100

Basis: deterministic technical candidate

Strongly consistent attempt; successful exploitation not observedDisclosure embargo completed
HIGH

Honeypot request semantics are strongly consistent with CVE-2017-9841. This identifies likely attack intent, not successful exploitation or execution.

STRONGLY COMPATIBLETechnical consistency 95/100

Basis: deterministic technical candidate

Strongly consistent attempt; successful exploitation not observedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 09:2716 Feb
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2017-9841.

  2. 00:0015 Feb
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Nuclei Templates v10.3.9 – Release Notes

New Templates Added: 182 | CVEs Added: 116 | First-time contributions: 7 🔥 Release Highlights 🔥 [ CVE-2026-25892 ] Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS ( @dhiyaneshdk ) [high] 🔥 [ CVE-2026-23744 ] MCPJam Inspector - Remote Code Execution ( @louay-075 ) [critical] 🔥 [ CVE-2026-22812 ] OpenCode &lt; 1.0.216 - Unauthenticated Remote Code Execution ( @princechaddha ) [high] 🔥 [CVE-2026-21891] ZimaOS - Authentication Bypass ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-21877 ] n8n &gt;= 0.123.0 and &lt; 1.121.3 - Remote Code Execution ( @s4e-io ) [critical] 🔥 [ CVE-2026-1731 ] BeyondTrust Remote Support - Unauth WebSocket RCE (@attackerkb, @hacktron , @pdteam ) [critical] (KEV) 🔥 [ CVE-2026-1207 ] Django RasterField - SQL Injection ( @omarkurt ) [high] 🔥 [ CVE-2025-54068 ] Laravel Livewire v3 - Remote Command Execution ( @flame-11 ) [critical] 🔥 [ CVE-2025-40551 ] SolarWinds Web Help Desk &lt; 2026.1 - Unauthenticated JNDI Injection RCE (@Horizon3.ai) [critical] (KEV) 🔥 [ CVE-2025-14528 ] D-Link DIR-803 - Authentication Bypass ( @dhiyaneshdk ) [high] 🔥 [ CVE-2025-2611 ] ICTBroadcast - Command Injection ( @Chocapikk ) [critical] (vKEV) 🔥 [ CVE-2024-8943 ] LatePoint &lt;= 5.0.12 - Authentication Bypass ( @daffainfo ) [critical] (vKEV) 🔥 [ CVE-2024-8911 ] LatePoint &lt;= 5.0.11 - SQL Injection ( @daffainfo ) [critical] (vKEV) 🔥 [ CVE-2024-6671 ] WhatsUp Gold GetStatisticalMonitorList SQLi - Authentication Bypass ( @daffainfo , @jjcho ) [critical] (vKEV) 🔥 [ CVE-2024-6250 ] LOLLMS WebUI - Absolute Path Traversal ( @ritikchaddha ) [high] 🔥 [ CVE-2024-0705 ] Stripe Payment Plugin for WooCommerce &lt;= 3.7.9 - Unauth SQL Injection ( @Shivam Kamboj) [critical] 🔥 [ CVE-2023-35708 ] MOVEit Transfer - SQL Injection ( @daffainfo , @jjcho ) [critical] (vKEV) 🔥 [ CVE-2022-31678 ] VMWare Cloud Foundation NSX-V - XML External Entity (XXE) ( @daffainfo ) [critical] (vKEV) 🔥 [ CVE-2022-3236 ] Sophos Firewall &lt;= 19.0 MR1 - Remote Code Execution ( @daffainfo ) [critical] (KEV) 🔥 [ CVE-2021-22017 ] vCenter Server - Improper Access Control ( @daffainfo ) [medium] (KEV) 🔥 [ CVE-2019-13608 ] Citrix StoreFront Server - XML External Entity ( @daffainfo ) [high] (KEV) 🔥 [ CVE-2017-9841 ] PHPUnit - Remote Code Execution (@Random_Robbie, @pikpikcu ) [critical] (KEV) 🔥 What's Changed Bug Fixes Fixed incorrect tag formatting (- appearing as a tag) in CVE-2019-17444 template (PR #15306 ) Fixed incorrect reference in authentik-panel template (PR #15298 ) Fixed port format in unauth-java-message-broker-detect template (PR #15117 ) Fixed tag formatting (double comma) in templates (PR #15118 ) Fixed formatting of tags in CVE-2019-5591 template (PR #15119 ) Fixed port used on CVE-2014-0160 Heartbleed — was testing port 443 twice instead of testing plain HTTP port (PR #14653 ) Fixed path for gude-default-login template (PR #15134 ) Moved CVE-2024-43283 .yaml to correct directory http/cves/2024 (PR #15100 ) Updated CVE-2025-68645 .yaml (PR #15109 ) Updated CVE-2024-13094 .yaml with new alert script (PR #15299 ) Updated CVE-2021-24527 .yaml (PR #14980 ) False Negatives Fixed false negative in CVE-2025-24963 on Linux targets (Ubuntu/Debian) due to strict /etc/passwd matching (PR #15301 , Issue #15205 ) False Positives Reduced false positives in wp-wps-hide-login-log template that triggered on non-WordPress SPA sites (PR #15096 , Issue #15089 ) Fixed false positives in CVE-2021-35042 matcher — status_code == 500 alone was triggering on generic 500 pages (PR #15250 ) Made matchers for weak-csp-detect more granular to avoid duplicate matching results (PR #15123 ) Improved weak CSP detection logic, fixed matcher conditions and corrected regex typo (PR #15014 ) Enhancements Enhanced Cisco UCM username enumeration template to extract usernames, emails, and phone numbers added 3 new Cisco UCM templates (PR #15049 ) Refactored Open WebUI template to make detection more generic (PR #15251 ) Rewrote templates from RAW HTTP to normal HTTP for clustering support, saving

CVE-2014-0160CVE-2017-9841CVE-2018-16363CVE-2019-13608CVE-2019-17444CVE-2019-5591CVE-2020-37123CVE-2021-22017CVE-2021-24139CVE-2021-24527CVE-2021-24786CVE-2021-35042CVE-2021-41097CVE-2022-28987CVE-2022-29495CVE-2022-31678CVE-2022-3236CVE-2022-3254CVE-2022-45836CVE-2023-24000CVE-2023-28787CVE-2023-3197CVE-2023-35708CVE-2023-44982CVE-2023-45648CVE-2023-5204CVE-2023-6970CVE-2024-0705CVE-2024-10152CVE-2024-11868CVE-2024-12585CVE-2024-12638CVE-2024-12724CVE-2024-12732CVE-2024-12734CVE-2024-12737CVE-2024-12749CVE-2024-12873CVE-2024-12878CVE-2024-13055CVE-2024-13094CVE-2024-13097CVE-2024-13098CVE-2024-13099CVE-2024-13112CVE-2024-13114CVE-2024-13219CVE-2024-13220CVE-2024-13221CVE-2024-13222CVE-2024-13224CVE-2024-13225CVE-2024-13226CVE-2024-13325CVE-2024-13326CVE-2024-13327CVE-2024-13328CVE-2024-13330CVE-2024-13331CVE-2024-13352CVE-2024-13492CVE-2024-13543CVE-2024-13569CVE-2024-13570CVE-2024-13609CVE-2024-13619CVE-2024-13625CVE-2024-13627CVE-2024-13628CVE-2024-13630CVE-2024-13634CVE-2024-13727CVE-2024-14015CVE-2024-1751CVE-2024-30490CVE-2024-32128CVE-2024-3231CVE-2024-3408CVE-2024-3605CVE-2024-37259CVE-2024-43283CVE-2024-5333CVE-2024-5483CVE-2024-6250CVE-2024-6265CVE-2024-6671CVE-2024-8911CVE-2024-8943CVE-2025-10090CVE-2025-10353CVE-2025-11368CVE-2025-1232CVE-2025-1303CVE-2025-13138CVE-2025-1338CVE-2025-13956CVE-2025-14155CVE-2025-14528CVE-2025-15503CVE-2025-22214CVE-2025-24582CVE-2025-24786CVE-2025-24963CVE-2025-2611CVE-2025-28242CVE-2025-32257CVE-2025-40551CVE-2025-4078CVE-2025-4652CVE-2025-54068CVE-2025-66744CVE-2025-68509CVE-2025-68645CVE-2025-8266CVE-2026-0594CVE-2026-1207CVE-2026-1731CVE-2026-21877CVE-2026-21891CVE-2026-22812CVE-2026-23744CVE-2026-24128CVE-2026-25892
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score50.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-94
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.