CISA Known Exploited Vulnerability

CVE-2012-1823

PHP · PHP

PHP-CGI Query String Parameter Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

Required action

Apply updates per vendor instructions.