CVE-2024-8926 is a command-injection vulnerability in PHP on Windows affecting PHP 8.1 before 8.1.30, PHP 8.2 before 8.2.24, and PHP 8.3 before 8.3.12. Under certain non-standard Windows codepage configurations, an attacker can bypass the fixes for CVE-2024-4577 through Windows Best Fit codepage behavior. The bypass permits malicious input to be interpreted as options supplied to the PHP binary, potentially exposing script source code or causing arbitrary PHP code to run on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
edu-recon is a Python 3.10+ reconnaissance, vulnerability-triage, and active assessment orchestrator aimed at education-sector engagements. It has 38 files, primarily Python modules, with `recon.py` as the CLI entry point and `run.sh` as a one-command launcher. Its stdlib web UI (`edurecon/webui.py`) exposes scan submission, live logs, findings, report/reproduction generation, and dump functions; it defaults to localhost but can be bound to all interfaces without authentication. The engine expands CIDRs through nmap ping sweeps and domains through subdomain enumeration, then concurrently runs Shodan enrichment, nmap service/version scanning, dirsearch web discovery, exposure checks, secret/API-key scanning, Moodle auditing, reflected-XSS and SQLi checks, Hydra credential attacks, and WordPress wp2shell processing. Full intensity actively invokes sqlmap and Hydra; recon mode lists those candidates instead. It uses external repositories installed by `setup` for PHP-CGI, React2Shell, WordPress, and directory-scanning capabilities. Built-in CVE probes target PHPUnit eval-stdin RCE (CVE-2017-9841), Apache traversal/LFI (CVE-2021-41773), Struts S2-045 (CVE-2017-5638), Confluence OGNL RCE (CVE-2022-26134), Drupalgeddon2 (CVE-2018-7600), Next.js middleware bypass (CVE-2025-29927), PHP-CGI (CVE-2024-4577/CVE-2024-8926), and React Server Components RCE (CVE-2025-55182). Several internal checks use benign confirmation markers/arithmetic oracles, but the overall repository is an active exploitation platform: full mode can perform credential guessing and injection, external wp2shell can pursue SQLi-to-shell, and React2Shell can be configured away from safe-check mode to run a command. Notable collection functionality includes downloading exposed files and backups, scanning their contents for cloud/VCS/payment/API credentials, and `gitdump.py`, which mirrors an exposed `.git` directory, retrieves reachable loose Git objects, and reconstructs source files. Artifacts, reports, findings, and potentially sensitive material are stored under `runs/<run-id>/`; report code serializes evidence and can therefore retain sensitive values. ScopeGuard supports target/CIDR and subdomain allowlisting, but supplied documentation/configuration describe scope enforcement as disabled by default, materially increasing operator-supplied target risk.
This repository is a comprehensive exploit toolkit targeting PHP-CGI parameter injection vulnerabilities, specifically CVE-2024-4577 and CVE-2024-8926. The main exploit logic resides in 'exploit.py', which provides a command-line interface for automated vulnerability scanning and exploitation. The tool supports multiple attack modes, including remote command execution, arbitrary PHP code execution, file upload, and file download. It allows users to specify target URLs and CGI endpoints, select or customize payloads, and optionally route traffic through Tor for anonymity. A notable feature is the modular bypass system: the 'bypass_manager.py' and the 'bypass_modules/' directory provide various tamper scripts to obfuscate payloads and evade WAFs or security controls. These modules can modify payloads, CGI paths, HTTP headers (e.g., randomizing User-Agent, adding X-Forwarded-For), and more. The tool also supports forced exploitation mode, detailed logging, and animated terminal output for usability. The repository is structured as follows: - 'exploit.py': Main exploit script and entry point. - 'bypass_manager.py' and 'bypass_modules/': Framework for WAF bypass and payload tampering. - 'tor_helper.py': Utilities for routing requests through Tor. - 'requirements.txt': Python dependencies. - 'README.md': Detailed usage instructions, attack modes, and legal disclaimer. The exploit is operational, providing real attack capabilities against vulnerable PHP-CGI deployments. It is not a detection-only script, but a full-featured exploitation tool with customizable payloads and bypass techniques. The main attack vector is network-based, targeting web servers exposing PHP-CGI endpoints. The tool is suitable for red team operations, CTFs, and security research.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.