← Back

CVE-2012-1823

Published: May 11, 2012Modified: Apr 21, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

Affected (30)

Products: Php: Php · Fedoraproject: Fedora · Debian: Debian Linux · +5 more
Show all products
1 product
Php
1 product
Fedora
1 product
Debian Linux
1 product
Hp Ux
1 product
Opensuse
2 products
Linux Enterprise Server
1 product
Mac Os X
9 products
Application Stack
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Workstation
Storage
Storage For Public Cloud
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Php
Before 5.3.12
From 5.4.0 to 5.4.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 39
Version 40
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Hp
Version b.11.23
Version b.11.31
Configuration E
7 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 11.4
Version 12.1
Suse
Version 10 sp4
Version 11 sp2
Version 11 sp2
Suse
Version 10 sp4
Version 11 sp2
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Apple
From 10.6.8 to 10.7.5
From 10.8.0 to 10.8.2
Configuration G
14 vulnerable

References (60)

Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing List
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
ExploitThird Party AdvisoryUS Government Resource
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: cret@cert.org
ExploitPatchRelease Notes
Source: cret@cert.org
Release Notes
Source: cret@cert.org
Broken LinkThird Party AdvisoryVDB Entry
Source: cret@cert.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploit
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.