CyberSec.Space Logo
Back to CVE Browser

CVE-2012-1823

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score82.3340%
EPSS Percentile92.28th
PublishedMay 11, 2012
Last ModifiedApr 21, 2026

Vulnerability Description

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

Affected Platforms (CPE)

πŸ“¦
Php

Php

< 5.3.12
πŸ“¦
Php

Php

>= 5.4.0 and < 5.4.2
πŸ’»
Fedoraproject

Fedora

= 39
πŸ’»
Fedoraproject

Fedora

= 40
πŸ’»
Debian

Debian Linux

= 6.0
πŸ’»
Hp

Hp Ux

= b.11.23
πŸ’»
Hp

Hp Ux

= b.11.31
πŸ’»
Opensuse

Opensuse

= 11.4
πŸ’»
Opensuse

Opensuse

= 12.1
πŸ’»
Suse

Linux Enterprise Server

= 10
πŸ’»
Suse

Linux Enterprise Server

= 11
πŸ’»
Suse

Linux Enterprise Server

= 11
πŸ’»
Suse

Linux Enterprise Software Development Kit

= 10
πŸ’»
Suse

Linux Enterprise Software Development Kit

= 11
πŸ’»
Apple

Mac Os X

>= 10.6.8 and < 10.7.5
πŸ’»
Apple

Mac Os X

>= 10.8.0 and < 10.8.2
πŸ“¦
Redhat

Application Stack

= 2.0
πŸ“¦
Redhat

Gluster Storage Server For On Premise

= 2.0
πŸ“¦
Redhat

Storage

= 2.0
πŸ“¦
Redhat

Storage For Public Cloud

= 2.0
πŸ’»
Redhat

Enterprise Linux Desktop

= 6.0
πŸ’»
Redhat

Enterprise Linux Eus

= 5.6
πŸ’»
Redhat

Enterprise Linux Eus

= 6.1
πŸ’»
Redhat

Enterprise Linux Eus

= 6.2
πŸ’»
Redhat

Enterprise Linux Server

= 5.0
πŸ’»
Redhat

Enterprise Linux Server

= 6.0
πŸ’»
Redhat

Enterprise Linux Server Aus

= 5.3
πŸ’»
Redhat

Enterprise Linux Server Aus

= 5.6
πŸ’»
Redhat

Enterprise Linux Workstation

= 5.0
πŸ’»
Redhat

Enterprise Linux Workstation

= 6.0

References & Advisories

Related Vulnerabilities