Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factKEV
Assessment
CVE-2017-9841 allows remote PHP code execution when a vulnerable PHPUnit eval-stdin endpoint is exposed. CISA KEV lists it as known to be exploited globally. The supplied exploit-source record does not describe this CVE, so it adds no useful exploit detail.
Why it matters
Successful exploitation can let an unauthenticated attacker run PHP code.
The affected endpoint is reachable when the PHPUnit vendor path is exposed to the web.
Evidence
1 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
No first-party telemetry is configured, so VTP observation is unknown.
The supplied exploit-source record is unrelated to this CVE.
CISA KEV confirms known global exploitation, not activity in a specific environment.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Review in your environment: if you use PHPUnit, check whether the eval-stdin.php path is externally reachable under a vendor directory.
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 1.00; this is predictive context, not exploitation evidence.
03
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
1publications detected
1underlying evidence chains
0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
04
Event history
Threat timeline
09:2716 Feb
EXPLOIT SOURCE UPDATE
New exploit-source update
ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2017-9841.
00:0015 Feb
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.