PT-2012-3959 · Php+2 · Php+2
Publicado
2012-05-11
·
Atualizado
2024-06-15
·
CVE-2012-2335
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP versions 5.3.12 and 5.4.2
Description
The issue allows remote attackers to bypass a protection mechanism and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi main.c component and a query string beginning with a +- sequence. This is due to php-wrapper.fcgi not properly handling command-line arguments.
Recommendations
For PHP version 5.3.12, update to a version that properly handles command-line arguments to prevent arbitrary code execution.
For PHP version 5.4.2, update to a version that properly handles command-line arguments to prevent arbitrary code execution.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hp-Ux
Php
Suse