CVE-2012-1823

CVE Published 2012-05-11
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) fedoraproject, hp, opensuse, apple, php, suse, debian, redhat
Related Product(s) enterprise_linux_workstation, enterprise_linux_desktop, gluster_storage_server_for_on-premise, mac_os_x, linux_enterprise_software_development_kit, debian_linux, application_stack, storage, opensuse, php, enterprise_linux_eus, enterprise_linux_server, linux_enterprise_server, fedora, enterprise_linux_server_aus, storage_for_public_cloud, hp-ux
Exploitation Reported (CISA KEV) 2022-03-25
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References