VDB

CISA-2012-1823

CISA-2012-1823 PUBLISHED CVSS 9.8 CRITICAL

Reported by certcc · Published May 11, 2012

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

Risk Scores

CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a

Timeline

  • May 11, 2012 CVE Published
  • Nov 4, 2025 CVE Updated
  • Mar 26, 2026 Distribution Patch
  • Mar 26, 2026 Security Advisory
  • Mar 26, 2026 Security Advisory
  • Mar 26, 2026 Security Advisory
  • Mar 26, 2026 Security Advisory
  • Mar 26, 2026 Security Advisory
  • Mar 26, 2026 Security Advisory

References

…and 11 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›