PT-2012-3959 · Php+2 · Php+2

Published

2012-05-11

·

Updated

2024-06-15

·

CVE-2012-2335

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions 5.3.12 and 5.4.2
Description The issue allows remote attackers to bypass a protection mechanism and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi main.c component and a query string beginning with a +- sequence. This is due to php-wrapper.fcgi not properly handling command-line arguments.
Recommendations For PHP version 5.3.12, update to a version that properly handles command-line arguments to prevent arbitrary code execution. For PHP version 5.4.2, update to a version that properly handles command-line arguments to prevent arbitrary code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2335
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
SUSE-SU-2012_0721-1

Affected Products

Hp-Ux
Php
Suse