This module exploits an argument injection vulnerability in PHP up to version 5.3.12 and 5.4.2 when running as a standalone CGI processor and takes advantage of the -d flag to achieve remote code execution.



This update adds support for FreeBSD, OpenBSD, RedHat and Windows platforms.
The vulnerability is caused due to a boundary error during the processing of TFTP Read/Write request packet types. This can be exploited to cause a stack-based buffer overflow by sending a specially crafted packet with an overly long filename field.

This update ensures that the program receives all data.

This update fixes an error on Impact v12.3.