Netskope Threat Labs

SERVER-WEBAPP PHP-CGI RCE exploit Attempt Detected

IPS-NPA

1 SID: 301009

Detects exploitation of the PHP-CGI argument injection flaw that runs code on the web server without authentication. The rule matches the crafted request parameters that public exploits use to inject php-cgi options and execute payloads.