CVE Database
/

CVE-2012-2335

Back to search

CVE-2012-2335

Published: May 11, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2012:0721
vendor-advisory
x_refsource_SUSE
SUSE-SU-2012:0840
vendor-advisory
x_refsource_SUSE
49014
third-party-advisory
x_refsource_SECUNIA
SSRT100992
vendor-advisory
x_refsource_HP
VU#520827
third-party-advisory
x_refsource_CERT-VN
HPSBMU02900
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now