Php Esm W900

A recently patched vulnerability (CVE-2019-11043) in PHP is being actively exploited by attackers to compromise NGINX web servers, threat intelligence firm Bad Packets hasconfirmed. Learn more:

For a successful exploitation, target servers must have the PHP-FPM (FastCGI Process Manager) feature enabled, but that combination is not as uncommon as initially believed.

The flaw was discovered by Wallarm researcher Andrew Danau during a Capture The Flag contest that took place in September 2019.

The link for this article located at HelpNetSecurity is no longer available.