Loading HuntDB...

PHP-CGI Query String Parameter Vulnerability

Added March 25, 2022 Due April 15, 2022 CVE-2012-1823
Overdue PHP / PHP CWE-20

Description

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
8 months ago