Junglewise Threat Intelligence

CVE-2012-1823: PHP-CGI Query String Parameter Vulnerability

CVE-2012-1823 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: PHP Group PHP. Vendors: PHP Group.

Executive brief

PHP-CGI (sapi/cgi/cgi_main.c) fails to properly handle query strings lacking an equals sign, allowing remote attackers to pass command-line options to the PHP interpreter. This flaw can be leveraged to execute arbitrary code on the host system.

Affected products

  • PHP Group PHP before 5.3.12, 5.4.x before 5.4.2

Timeline

  • 2012-05-03: patched: PHP 5.4.2 released with fix.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats