Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-1823


sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.


Published

2012-05-11T10:15:48.043

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application php php < 5.3.12 Yes
Application php php < 5.4.2 Yes
Operating System fedoraproject fedora 39 Yes
Operating System fedoraproject fedora 40 Yes
Operating System debian debian_linux 6.0 Yes
Operating System hp hp-ux b.11.23 Yes
Operating System hp hp-ux b.11.31 Yes
Operating System opensuse opensuse 11.4 Yes
Operating System opensuse opensuse 12.1 Yes
Operating System suse linux_enterprise_server 10 Yes
Operating System suse linux_enterprise_server 11 Yes
Operating System suse linux_enterprise_server 11 Yes
Operating System suse linux_enterprise_software_development_kit 10 Yes
Operating System suse linux_enterprise_software_development_kit 11 Yes
Operating System apple mac_os_x < 10.7.5 Yes
Operating System apple mac_os_x < 10.8.2 Yes
Application redhat application_stack 2.0 Yes
Application redhat gluster_storage_server_for_on-premise 2.0 Yes
Application redhat storage 2.0 Yes
Application redhat storage_for_public_cloud 2.0 Yes
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_eus 5.6 Yes
Operating System redhat enterprise_linux_eus 6.1 Yes
Operating System redhat enterprise_linux_eus 6.2 Yes
Operating System redhat enterprise_linux_server 5.0 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_server_aus 5.3 Yes
Operating System redhat enterprise_linux_server_aus 5.6 Yes
Operating System redhat enterprise_linux_workstation 5.0 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes

References