CVE-2012-2335

php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:5.3.12:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:38

Type Values Removed Values Added
References () http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/ - () http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/ -
References () http://git.php.net/?p=php-src.git%3Ba=blob%3Bf=sapi/cgi/cgi_main.c%3Bh=a7ac26f0#l1569 - () http://git.php.net/?p=php-src.git%3Ba=blob%3Bf=sapi/cgi/cgi_main.c%3Bh=a7ac26f0#l1569 -
References () http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00004.html - () http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00004.html -
References () http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.html - () http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00003.html -
References () http://secunia.com/advisories/49014 - () http://secunia.com/advisories/49014 -
References () http://www.kb.cert.org/vuls/id/520827 - US Government Resource () http://www.kb.cert.org/vuls/id/520827 - US Government Resource
References () http://www.php.net/archive/2012.php#id2012-05-06-1 - () http://www.php.net/archive/2012.php#id2012-05-06-1 -
References () https://bugs.php.net/bug.php?id=61910 - Vendor Advisory () https://bugs.php.net/bug.php?id=61910 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/75652 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/75652 -
References () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862 - () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862 -

Information

Published : 2012-05-11 10:15

Updated : 2024-11-21 01:38


NVD link : CVE-2012-2335

Mitre link : CVE-2012-2335

CVE.ORG link : CVE-2012-2335


JSON object : View

Products Affected

php

  • php
CWE
CWE-264

Permissions, Privileges, and Access Controls