S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 24, 2025

CVE-2019-9082 Scanner

CVE-2019-9082 Scanner - Remote Code Execution (RCE) vulnerability in ThinkPHP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-9082
8.8
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ThinkPHP is a popular open-source PHP framework used for developing web applications quickly and efficiently. Its simplicity and powerful features make it a preferred choice for web developers in various domains, from small startups to large enterprises. ThinkPHP is utilized by developers for creating robust and scalable applications across diverse industries. It provides an agile development structure that streamlines processes and encourages best practices. Given its wide usage, security in ThinkPHP's functionalities and deployment becomes critical. Version control is essential to mitigate vulnerabilities and ensure the safety of web applications built with ThinkPHP.

Remote Code Execution (RCE) is a severe vulnerability allowing attackers to execute arbitrary commands on a targeted system. This vulnerability is critical because it can lead to a full system compromise when exploited. Attackers can execute malicious scripts, access confidential data, or disrupt services. It's commonly associated with security weaknesses within some web frameworks, which fail to handle system calls or external commands correctly. Addressing RCE vulnerabilities is crucial for maintaining the integrity and security of applications in production environments. Recognized for its destructive potential, it stresses the importance of regular security assessments and updates.

The RCE vulnerability in ThinkPHP, specifically version < 3.2.4, occurs due to improper handling of inputs in specific endpoints. Exploitation is achievable via the 's' parameter in the index.php file using the invokefunction functionality. An attacker can manipulate function calls to execute arbitrary system commands without authentication, leveraging this gap in security. The endpoint's lack of input sanitization allows malicious payloads, such as command injections, to occur. Specific to this vulnerability, attackers can utilize crafted HTTP requests to trigger unwanted command executions. Its ease of exploitation highlights the necessity of implementing robust input validation mechanisms.

If exploited, the vulnerability can lead to significant consequences, including unauthorized access to sensitive data, disruptions in application services, and complete system takeovers. Attackers could gain administrative privileges, allowing them to alter system configurations or deploy further malicious activities within the network. Such intrusions can result in financial losses, reputational damage, and potential legal implications for affected organizations. The exploitation of RCE vulnerabilities is frequently associated with data breaches and identity theft. Therefore, organizations using affected versions need immediate remediation to limit exposure and safeguard their assets.

REFERENCES

Solution Advice
  • Upgrade ThinkPHP to version 3.2.4 or later to patch the vulnerability.
  • Apply vendor-specific security patches if available.
  • Implement a web application firewall (WAF) to filter out malicious requests.
  • Regularly update and audit your software to prevent potential exploits.
  • Use secure coding practices and input validation to avert command injections.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.