CVE-2019-11043
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
9.8
CVSS 3.1
99.8 %
EPSS (current)
2022-03-25
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: PHP / FastCGI Process Manager (FPM)
Published: 2019-10-28 · Due (CISA): 2022-04-15
CWE: CWE-787 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2019/CVE-2019-11043.yaml | PHP-FPM Path Info Buffer Underflow - Remote Code Execution | – |
| metasploit | exploit/multi/http/php_fpm_rce | exploit/multi/http/php_fpm_rce | 2019-10-22 |
| exploitdb | 47553 | PHP-FPM + Nginx - Remote Code Execution | 2019-10-28 |
| exploitdb | 48182 | PHP-FPM - Underflow Remote Code Execution (Metasploit) | 2020-03-09 |
References only — no downloads or instructions.