[language-switcher]
[language-switcher]

Remote Code Execution | PHP7 w/ NGINX – Webcare360

by Olivia Hefner
press C image

Discussion:

A recently patched security flaw in modern versions of the PHP programming language is being exploited in the wild to take over servers, ZDNet has learned from threat intelligence firm Bad Packets.

The vulnerability is a remote code execution (RCE) in PHP 7, the newer branch of PHP, the most common programming language used to build websites. The issue, tracked as CVE-2019-11043, lets attackers run commands on servers just by accessing a specially-crafted URL.

Fortunately, not all PHP-capable web servers are impacted. Only NGINX servers with PHP-FPM enabled are vulnerable. PHP-FPM, or FastCGI Process Manager, is an alternative PHP FastCGI implementation with some additional features.

References:

https://www.zdnet.com/article/nasty-php7-remote-code-execution-bug-exploited-in-the-wild/

https://bugs.php.net/bug.php?id=78599

Related Blogs

Best OffshoreDedi Alternatives

Best OffshoreDedi Alternatives & Competitors in 2026

OffshoreDedi is a hosting provider specializing in offshore VPS and dedicated server solutions for users seeking privacy, flexible hosting environments, and alternative jurisdiction options. Its

Best DarkHost Alternatives & Competitors in 2026

Best DarkHost Alternatives & Competitors in 2026

DarkHost has built a reputation in the offshore hosting space as a provider focused on privacy-first infrastructure, VPS solutions, anonymous account creation, and crypto-friendly payments.

Best TheOnionHost Alternatives & Competitors

Best TheOnionHost Alternatives & Competitors in 2026

Finding a reliable privacy-focused hosting provider has become increasingly important for website owners, cryptocurrency businesses, developers, independent publishers, and organizations operating in sensitive industries. While

CONNECT

Stay in the Loop