PHP.URI.Code.Injection

description-logoDescription

This indicates an attempt to exploit a remote code execution vulnerability in PHP.
The vulnerability may allow attackers to execute arbitrary code on remote systems by including PHP sequences in some parameters.

affected-products-logoAffected Products

Any website that runs any PHP software which allows remote code execution is vulnerable.

Impact logoImpact

System compromise: remote PHP code execution.

recomended-action-logoRecommended Actions

If a FortiGate with FortiOS 2.80 or above is used, select "drop" as the default action for the signature.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-05-03 18.071 Sig Added
2019-08-27 14.677 Default_action:pass:drop
2019-07-31 14.662 Sig Added
2019-05-21 14.617 Status:disable:enable
2019-05-15 14.614 Sig Added
2019-05-10 14.612 Sig Added
2019-05-07 14.608 Sig Added