CVE Database
/

CVE-2012-2311

Back to search

CVE-2012-2311

Published: May 11, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

VendorProductVersions

n/a

n/a

affected
n/a

References

SSRT100856
vendor-advisory
x_refsource_HP
SUSE-SU-2012:0604
vendor-advisory
x_refsource_SUSE
1027022
vdb-entry
x_refsource_SECTRACK
openSUSE-SU-2012:0590
vendor-advisory
x_refsource_SUSE
49014
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2012:0598
vendor-advisory
x_refsource_SUSE
APPLE-SA-2012-09-19-2
vendor-advisory
x_refsource_APPLE
SSRT100992
vendor-advisory
x_refsource_HP
VU#520827
third-party-advisory
x_refsource_CERT-VN
HPSBUX02791
vendor-advisory
x_refsource_HP
DSA-2465
vendor-advisory
x_refsource_DEBIAN
49085
third-party-advisory
x_refsource_SECUNIA
HPSBMU02900
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2012-2311 - Security Vulnerability | QwikSec