CVE-2012-1823

CVE Published 2012-05-11
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) fedoraproject, hp, redhat, php, suse, apple, opensuse, debian
Related Product(s) storage, enterprise_linux_server_aus, php, mac_os_x, application_stack, enterprise_linux_workstation, enterprise_linux_eus, fedora, enterprise_linux_server, gluster_storage_server_for_on-premise, hp-ux, storage_for_public_cloud, linux_enterprise_server, debian_linux, opensuse, linux_enterprise_software_development_kit, enterprise_linux_desktop
Exploitation Reported (CISA KEV) 2022-03-25
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References