CVE-2012-0831
Trois vulnérabilités ont été corrigées dans <span class="textit">PHP</span>. Deux d'entre-elles concernent les branches 5.3.x et 5.4.x. La dernière (CVE-2012-0831) ne concerne que la branche 5.3.x et corrige un problème lié à <span class="textit">magic_quote_gpc</span> lors du chargement de variables d'environnement, ce qui peut faciliter l'injection de requête SQL par un attaquant distant.
EPSS 10.63% · 93.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PHP | PHP |
Timeline
- Sep 16, 2010 PoC Published
- Feb 10, 2012 CVE Published
- Sep 6, 2015 PoC Published
- Oct 9, 2020 PoC Published
- Feb 4, 2022 EPSS Score
- Aug 31, 2022 PoC Published
- Feb 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- Apr 2, 2025 EPSS Score
- Apr 7, 2025 EPSS Score
References
- https://cert.ssi.gouv.fr/avis/CERTA-2012-AVI-244/ advisory
- http://www.php.net/archive/2012.php#id2012-04-26-1 advisory
- https://cert.ssi.gouv.fr/avis/CERTA-2012-AVI-512/ advisory
- https://cert.ssi.gouv.fr/avis/CERTFR-2014-AVI-480/ advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10661 advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10657 advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10658 advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10659 advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10660 advisory