Executive brief
PHP-CGI (sapi/cgi/cgi_main.c) fails to properly handle query strings lacking an equals sign, allowing remote attackers to pass command-line options to the PHP interpreter. This flaw can be leveraged to execute arbitrary code on the host system.
Affected products
- PHP Group PHP before 5.3.12, 5.4.x before 5.4.2
Timeline
- 2012-05-03: patched: PHP 5.4.2 released with fix.
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.