{"id":116414,"date":"2024-06-07T12:05:45","date_gmt":"2024-06-07T10:05:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-php-pozvolyayushhaya-vypolnit-kod-pri-rabote-v-rezhime-cgi"},"modified":"2024-06-07T12:05:45","modified_gmt":"2024-06-07T10:05:45","slug":"uyazvimost-v-php-pozvolyayushhaya-vypolnit-kod-pri-rabote-v-rezhime-cgi","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-php-pozvolyayushhaya-vypolnit-kod-pri-rabote-v-rezhime-cgi","title":{"rendered":"Eine Schwachstelle in PHP, die die Ausf\u00fchrung von Code im CGI-Modus erm\u00f6glicht.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In PHP wurde eine Schwachstelle (CVE-2024-4577) entdeckt, die die Ausf\u00fchrung eigenen Codes auf dem Server oder die Einsicht in den Quellcode von PHP-Skripten erm\u00f6glicht, wenn PHP im CGI-Modus auf der Windows-Plattform verwendet wird (Konfigurationen mit mod_php, php-fpm und FastCGI sind nicht betroffen). Das Problem wurde in den Versionen PHP 8.3.8, 8.2.20 und 8.1.29 behoben.<\/p>\n<p>Die Schwachstelle ist ein Sonderfall eines Problems, das 2012 behoben wurde (CVE-2012-1823), und der Schutz, der zu diesem Zweck hinzugef\u00fcgt wurde, war nicht ausreichend, um einen Angriff auf der Windows-Plattform zu verhindern. Die Angriffsart besteht darin, das Argument der Befehlszeile beim Start des PHP-Interpreters durch Manipulation von Anfrageparametern an ein PHP-Skript einzuschleusen. <\/p>\n<p>Bei der alten Schwachstelle CVE-2012-1823 gen\u00fcgte es, Befehlszeilenoptionen anstelle von Anfrageparametern anzugeben, z. B. \u201ehttp:\/\/localhost\/index.php?-s\u201c um den Quellcode des Skripts anzuzeigen. Die neue Schwachstelle basiert darauf, dass die Windows-Plattform die automatische Umwandlung von Zeichen vornimmt, was es erm\u00f6glicht, Zeichen anzugeben, die in bestimmten Kodierungen vorhanden sind und durch das Zeichen \u201e-\u201e (z. B. http:\/\/localhost\/index.php?s) ersetzt werden. <\/p>\n<p>Die Schwachstelle wurde in Konfigurationen mit Lokalisierungen f\u00fcr Traditionelles Chinesisch (cp950), Vereinfachtes Chinesisch (cp936) und Japanisch (cp932) best\u00e4tigt, jedoch ist ihr Auftreten auch bei anderen Lokalisierungen nicht ausgeschlossen. Das Problem tritt in der Standardkonfiguration des XAMPP-Pakets (Apache + MariaDB + PHP + Perl) sowie in allen Apache-Konfigurationen auf, in denen php-cgi als Handler f\u00fcr CGI-Skripte \u00fcber die Konfiguration eingestellt ist.<br \/>\n\u2018Action cgi-script \u201a\/cgi-bin\/php-cgi.exe\u2018 oder \u201aAction application\/x-httpd-php-cgi \u201a\/php-cgi\/php-cgi.exe\u2018, oder bei direkter Platzierung des php-Interpreters in \u201a\/cgi-bin\u2018 und in allen anderen Verzeichnissen, in denen die Ausf\u00fchrung von CGI-Skripten \u00fcber die Direktive ScriptAlias erlaubt ist.<\/p>\n<p>Dar\u00fcber hinaus wurden in den Updates PHP 8.3.8, 8.2.20 und 8.1.29 noch drei weitere Schwachstellen behoben: <\/p>\n<ul>\n<li class=\"l\"> CVE-2024-5458 \u2014 M\u00f6glichkeit der Umgehung der Filterung<br \/>\n   FILTER_VALIDATE_URL, der bei der Verwendung der Funktion filter_var aufgerufen wird.<\/p>\n<li class=\"l\">  CVE-2024-5585 \u2014 alternativer Angriffsvektor f\u00fcr die Schwachstelle CVE-2024-1874, der es erm\u00f6glicht, den zuvor hinzugef\u00fcgten Schutz zu umgehen und Befehlsersetzungen bei der Aufruf von bat- und cmd-Dateien \u00fcber die Funktion proc_open auf der Windows-Plattform durchzuf\u00fchren (Schwachstelle BatBadBut).\n<li class=\"l\"> Die Funktion openssl_private_decrypt ist anf\u00e4llig f\u00fcr Angriffe von Marvin.\n<\/ul>\n<p>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=61332\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 PHP \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-4577), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0438\u043b\u0438 \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 PHP-\u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f PHP \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 CGI \u043d\u0430 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0435 Windows (\u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0441 mod_php, php-fpm \u0438 FastCGI \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043d\u0435 \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b). \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 PHP 8.3.8, 8.2.20 \u0438 8.1.29. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0447\u0430\u0441\u0442\u043d\u044b\u043c \u0441\u043b\u0443\u0447\u0430\u0435\u043c \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 2012 \u0433\u043e\u0434\u0443 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b CVE-2012-1823, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-116414","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 PHP \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-4577), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0438\u043b\u0438 \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 PHP-\u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f PHP \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 CGI \u043d\u0430 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0435 Windows (\u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0441.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-php-pozvolyayushhaya-vypolnit-kod-pri-rabote-v-rezhime-cgi\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 PHP, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u0440\u0430\u0431\u043e\u0442\u0435 \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 CGI | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 PHP \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-4577), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0438\u043b\u0438 \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 PHP-\u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f PHP \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 CGI \u043d\u0430 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0435 Windows (\u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0441.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-php-pozvolyayushhaya-vypolnit-kod-pri-rabote-v-rezhime-cgi\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-06-07T10:05:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-06-07T10:05:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Schwachstelle in PHP, die die Ausf\u00fchrung von Code im CGI-Modus erm\u00f6glicht | ProHoster","description":"In PHP wurde eine Schwachstelle (CVE-2024-4577) entdeckt, die es erm\u00f6glicht, eigenen Code auf dem Server auszuf\u00fchren oder den Quellcode des PHP-Skripts anzuzeigen, wenn PHP im CGI-Modus auf Windows-Plattformen (Konfigurationen mit) verwendet wird.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-php-pozvolyayushhaya-vypolnit-kod-pri-rabote-v-rezhime-cgi","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 PHP, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u0440\u0430\u0431\u043e\u0442\u0435 \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 CGI | ProHoster","og:description":"\u0412 PHP \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-4577), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0438\u043b\u0438 \u043f\u0440\u043e\u0441\u043c\u043e\u0442\u0440\u0430 \u0438\u0441\u0445\u043e\u0434\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 PHP-\u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f PHP \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 CGI \u043d\u0430 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0435 Windows (\u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0441.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-php-pozvolyayushhaya-vypolnit-kod-pri-rabote-v-rezhime-cgi","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-06-07T10:05:45+00:00","article:modified_time":"2024-06-07T10:05:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"116414","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 01:56:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 01:56:19","updated":"2026-01-23 01:56:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/116414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=116414"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/116414\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=116414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=116414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=116414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}