← Back to CVE List
Vulnerability Intelligence Report
PHP-CGI Query String Parameter Vulnerability

CVE-2012-1823

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-77 ↗CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
php php all
fedoraproject fedora 39, 40
debian debian_linux 6.0
hp hp-ux b.11.23, b.11.31
opensuse opensuse 11.4, 12.1
suse linux_enterprise_server 10, 11
suse linux_enterprise_software_development_kit 10, 11
apple mac_os_x all
redhat application_stack 2.0
redhat gluster_storage_server_for_on-premise 2.0
redhat storage 2.0
redhat storage_for_public_cloud 2.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_eus 5.6, 6.1, 6.2
redhat enterprise_linux_server 5.0, 6.0
redhat enterprise_linux_server_aus 5.3, 5.6
redhat enterprise_linux_workstation 5.0, 6.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.998%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2012-03-21T00:00:00
Published2012-05-11T10:00:00
Patch Date2012-05-03
Last Updated2025-11-04T17:11:54

LINK COPIED TO CLIPBOARD