PT-2012-3959 · Php+2 · Php+2
Published
2012-05-11
·
Updated
2024-06-15
·
CVE-2012-2335
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP versions 5.3.12 and 5.4.2
Description
The issue allows remote attackers to bypass a protection mechanism and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi main.c component and a query string beginning with a +- sequence. This is due to php-wrapper.fcgi not properly handling command-line arguments.
Recommendations
For PHP version 5.3.12, update to a version that properly handles command-line arguments to prevent arbitrary code execution.
For PHP version 5.4.2, update to a version that properly handles command-line arguments to prevent arbitrary code execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp-Ux
Php
Suse