PT-2012-3959 · Php+2 · Php+2

Publicado

2012-05-11

·

Atualizado

2024-06-15

·

CVE-2012-2335

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 5.3.12 and 5.4.2
Description The issue allows remote attackers to bypass a protection mechanism and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi main.c component and a query string beginning with a +- sequence. This is due to php-wrapper.fcgi not properly handling command-line arguments.
Recommendations For PHP version 5.3.12, update to a version that properly handles command-line arguments to prevent arbitrary code execution. For PHP version 5.4.2, update to a version that properly handles command-line arguments to prevent arbitrary code execution.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-2335
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
SUSE-SU-2012_0721-1

Produtos afetados

Hp-Ux
Php
Suse