Executive brief
PHP-CGI on Windows contains an OS command injection vulnerability due to 'Best-Fit' character replacement in certain code pages. This allows remote attackers to bypass previous protections (CVE-2012-1823) and execute arbitrary PHP code or disclose source code by passing malicious options to the PHP binary.
Affected products
- PHP Group PHP 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8
Timeline
- 2024-06-06: disclosed: Initial security alert by DEVCORE
- 2024-06-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-06-12: advisory: NVD publication date