CVE-2019-11043 is an integer-underflow and out-of-bounds write vulnerability in PHP-FPM PATH_INFO processing. In affected PHP releases, a newline-containing request URI can cause NGINX to pass an empty PATH_INFO value under vulnerable FastCGI configurations. PHP-FPM then underflows while reconstructing PATH_INFO and writes a null byte before the intended buffer. Researchers demonstrated that this primitive can corrupt FastCGI environment-buffer state and overwrite an environment-variable entry with PHP_VALUE, allowing attacker-controlled PHP configuration directives to be processed and enabling remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
Repository contains 2 files: a small Python exploit script and a README describing CVE-2019-11043. The main code file, 'CVE-2019-11043 .py', is a minimal interactive proof-of-concept that imports requests, accepts a target URL from the command line, and enters a loop prompting for commands. For each command, it sends an HTTP GET request to the supplied target with a crafted header named 'User-Agentt' containing the string "zerodiumsystem(' <cmd> ');" and then prints the beginning of the response body up to the first '<' character. The intended purpose is to provide a rudimentary remote shell against a web server believed to be vulnerable to CVE-2019-11043. Notable limitations: the script does not implement the actual request shaping, path/query manipulation, or environment discovery normally associated with reliable exploitation of CVE-2019-11043; it performs no vulnerability check, no target fingerprinting, and no error handling beyond basic argument presence. Despite these shortcomings, it is clearly intended as an exploit rather than a detector, because it accepts arbitrary commands and attempts to execute them remotely. The only fingerprintable network target is the operator-provided URL; no hardcoded IPs, domains, or external callbacks are present.
This repository contains a Python port of the ExploitDB PoC for CVE-2019-11043, a critical vulnerability in PHP-FPM when used with Nginx. The main file, cve201911043.py, is a standalone exploit script that automates the process of detecting vulnerable parameters, crafting malicious HTTP requests, and achieving remote code execution (RCE) on the target server. The exploit works by manipulating the request URI and headers to inject PHP configuration directives and ultimately execute arbitrary shell commands. The script includes logic for writing a PHP payload to the web root, executing test commands (such as 'whoami'), and cleaning up after exploitation by deleting the payload and reverting PHP settings. The default target is set to 127.0.0.1:80/index.php, but this can be modified. The exploit is operational and provides full RCE if the target is vulnerable. The repository is structured simply, with a single Python exploit file, a README, LICENSE, and .gitignore.
This repository contains a Go-based exploit for CVE-2019-11043, a critical vulnerability in PHP-FPM when used with nginx under certain configurations. The exploit targets servers running PHP 7+ with nginx, where the nginx configuration forwards PHP files to php-fpm without proper file existence checks and allows manipulation of the PATH_INFO variable. The exploit works by sending specially crafted HTTP requests to the target .php file, manipulating PHP-FPM settings to allow arbitrary code execution. The main logic is implemented in Go files (main.go, attack.go, detect.go, phpini.go, requester.go), with supporting files for detection and configuration. The repository also includes a Docker-based test environment (reproducer directory) to facilitate local testing and reproduction of the vulnerability. The exploit, once successful, allows the attacker to execute arbitrary shell commands on the target server by appending a query string to the PHP script URL. The code is operational and provides both detection and exploitation capabilities, with clear instructions and examples in the README. Notable endpoints include the test PHP script, temporary files used for code injection, and the FastCGI endpoint for PHP-FPM.
This repository contains a single Python script named 'CVE-2019-11043 .py' that exploits the CVE-2019-11043 vulnerability in PHP-FPM when used with certain Nginx configurations. The script provides an interactive shell-like interface, allowing the user to send arbitrary commands to the target server. It does this by sending HTTP GET requests to the user-supplied target URL, with a specially crafted 'User-Agentt' header containing PHP code to execute the specified command. The script prints the output of the command execution, up to the first '<' character in the response. The exploit requires the attacker to know the vulnerable target URL. The repository is minimal, containing only this exploit script, and is written in Python. No hardcoded endpoints are present; the target is supplied at runtime.
This repository contains a single Metasploit module (modules/exploits/multi/http/php_fpm_rce.rb) that exploits CVE-2019-11043, a remote code execution vulnerability in PHP-FPM when used with Nginx and certain configurations. The exploit works by sending specially crafted HTTP requests to a PHP page (default: /index.php) on the target server, manipulating PHP INI settings to create a file on disk that enables code execution via query string parameters. The module automatically detects the required parameters to trigger the vulnerability, executes the payload (either PHP code or shell commands), and performs cleanup by removing the created file and killing PHP-FPM worker processes. The exploit is weaponized, supporting customizable payloads and full integration with the Metasploit framework. The main attack vector is network-based, targeting HTTP endpoints exposed by vulnerable Nginx + PHP-FPM configurations. The only fingerprintable endpoints are the HTTP path to the PHP page (default /index.php) and the temporary file created in /tmp on the target system.
This repository provides resources and instructions for exploiting CVE-2019-11043, a remote code execution vulnerability affecting PHP-FPM when used with Nginx under certain configurations. The main exploit is not included directly but references the 'phuip-fpizdam' tool (written in Go) for exploitation, and provides a Python script ('php-rce-check.py') to check for vulnerability. The README details installation steps for the exploit tool, Docker-based vulnerable environment setup, and example usage against a test server. The Python script sends crafted HTTP requests to detect vulnerable servers by observing HTTP response codes. The repository targets Nginx servers running PHP-FPM (notably PHP 7.2.10 and Nginx 1.19.2 as per examples) and provides configuration and endpoint details relevant to the exploit. No weaponized or framework-based exploit is present; the repository serves as a proof-of-concept and vulnerability checker.
This repository provides a working proof-of-concept exploit for CVE-2019-11043, a critical vulnerability in PHP-FPM when used with NGINX under certain configurations. The exploit is implemented in Python (exploit.py) and automates the process of discovering vulnerable query string lengths and header values to trigger a buffer overflow in the FastCGI protocol handling. This allows the attacker to overwrite FastCGI variables, inject malicious PHP configuration directives, and ultimately achieve remote code execution (RCE) on the target server. The repository includes a Docker-based test environment with NGINX and PHP-FPM configured to be vulnerable, as well as a minimal PHP script (index.php) for demonstration. The main attack vector is network-based, targeting HTTP endpoints exposed by the web server. The exploit is operational and demonstrates full RCE, but is not weaponized for mass exploitation. The README provides detailed background, setup instructions, and analysis of the vulnerability and exploitation process.
This repository contains a Go-based exploit for CVE-2019-11043, a critical vulnerability in PHP-FPM when used with nginx under certain configurations. The exploit targets servers running PHP 7+ with nginx, where the nginx configuration forwards PHP requests to PHP-FPM without proper file existence checks and with specific fastcgi_param settings. The exploit works by manipulating the PATH_INFO and other FastCGI parameters to trigger a buffer underflow, allowing the attacker to set arbitrary php.ini values and ultimately achieve remote code execution (RCE). The repository is structured as follows: - Main exploit logic is implemented in Go files (main.go, attack.go, detect.go, detect_methods.go, phpini.go, requester.go, consts.go). - The exploit detects vulnerable configurations, determines the required parameters (QSL and Pisos), and then performs the attack by setting malicious php.ini values and executing arbitrary shell commands via HTTP requests. - A 'reproducer' directory contains Docker resources (Dockerfile, nginx and php-fpm configs, entrypoint script, and a test PHP file) to set up a local vulnerable environment for testing the exploit. The exploit is operational and provides full RCE if the target is vulnerable. It does not belong to a framework and is a standalone tool. The main entry point is main.go, which provides a CLI for running the exploit against a target URL. The README.md provides detailed usage instructions, configuration requirements, and reproduction steps. Notable endpoints include the test PHP script, temporary files used for payload delivery, and the FastCGI endpoint for PHP-FPM.
This repository contains a Python exploit script (cve_2019_11043.py) and a README for CVE-2019-11043, a critical vulnerability in certain PHP-FPM configurations behind Nginx. The exploit targets PHP versions 7.1.x < 7.1.33, 7.2.x < 7.2.24, and 7.3.x < 7.3.11, where improper handling of crafted HTTP requests allows attackers to set arbitrary PHP configuration directives via the fastcgi interface. The script first probes the target to determine if it is vulnerable by manipulating HTTP headers and query string lengths, then executes a series of payloads to set PHP directives that enable remote code execution. The attacker can then execute arbitrary system commands by passing them in the 'a' GET parameter. The README provides usage instructions and the required Nginx configuration for the vulnerability to be exploitable. The main attack vector is network-based, targeting web servers with vulnerable PHP-FPM configurations. The script is operational and provides a working exploit for remote code execution.
This repository provides a Python proof-of-concept exploit for CVE-2019-11043, a vulnerability in PHP-FPM when used with nginx. The exploit (exploit.py) automates the process of discovering the correct query string length and header value length to trigger the vulnerability, then injects malicious PHP settings to enable remote code execution (RCE). The payload allows the attacker to execute arbitrary shell commands on the target server via HTTP requests. The repository includes a docker-compose setup for a vulnerable nginx + PHP-FPM environment and a minimal PHP file for testing. The exploit is network-based and targets web servers running vulnerable configurations. The code is a functional PoC and not weaponized, but demonstrates the full RCE chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability caused by a path_info buffer underflow in PHP-FPM.
PHP-FPM remote code execution vulnerability referenced via an exploit repository found in the operator's toolkit.
A PHP-FPM buffer-underflow vulnerability in certain Nginx configurations. An empty PATH_INFO can cause a one-byte NULL write before the intended buffer; exploitation can corrupt FastCGI parameter structures and achieve remote code execution.
A remote code execution vulnerability in PHP-FPM affecting default Nextcloud NGINX configurations, identified as the likely initial access vector used to deploy NextCry ransomware against Nextcloud servers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.