peter bassill · operator
$ cve CVE-2012-1823 JSON

CVE-2012-1823 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-77
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2012-05-11
Last modified2026-06-16

CISA KEV

NamePHP-CGI Query String Parameter Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productPHP / PHP
Ransomware usenone reported

Affected (17)

VendorProduct
applemac os x
debiandebian linux
fedoraprojectfedora
hphp-ux
opensuseopensuse
phpphp
redhatapplication stack
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation
redhatgluster storage server for on-premise
redhatstorage
redhatstorage for public cloud
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD