php-code-execution

1 article
sort: new top best
clear filter
0 8/10

A critical RCE vulnerability in Sucuri's server-side scanner was discovered where disabled SSL certificate verification (CURLOPT_SSL_VERIFYPEER=false) allowed a MiTM attacker to inject arbitrary PHP code execution on customer servers. The report also documents Sucuri's poor handling of the disclosure, including six months of silence, underpayment of the bounty, and dismissal of legitimate attack scenarios.

Sucuri HackerOne Julien Ahrens CURLOPT_SSL_VERIFYPEER NSA Google PCI DSS
rcesecurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details