A AegiFlow
CRITICALCVSS 9.8KNOWN EXPLOITED

CVE-2012-1823

CVE-2012-1823 updated by NVD

Published
2022-03-25
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

Affected packages

EcosystemPackageAffected versionsFixed versions
PHPphp[object Object], [object Object]

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.