CVE-2012-1823 vulnerability in PHP and Other Products
Published on May 11, 2012








Known Exploited Vulnerability
This PHP-CGI Query String Parameter Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
The following remediation steps are recommended / required by April 15, 2022: Apply updates per vendor instructions.
Vulnerability Analysis
CVE-2012-1823 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
What is a Command Injection Vulnerability?
The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVE-2012-1823 has been classified to as a Command Injection vulnerability or weakness.
Products Associated with CVE-2012-1823
You can be notified by stack.watch whenever vulnerabilities like CVE-2012-1823 are published in these products:
What versions are vulnerable to CVE-2012-1823?
-
PHP Version 5.4.0 Fixed in Version 5.4.2
-
PHP Fixed in Version 5.3.12
-
Fedora Project Fedora Version 39
-
Fedora Project Fedora Version 40
-
Debian Linux Version 6.0
-
Hp Ux Version b.11.31
-
Hp Ux Version b.11.23
-
OpenSuse Version 11.4
-
OpenSuse Version 12.1
-
Suse Linux Enterprise Server Version 11 sp2 vmware
-
Suse Linux Enterprise Software Development Kit Version 11 sp2
-
Suse Linux Enterprise Server Version 11 sp2 -
-
Suse Linux Enterprise Software Development Kit Version 10 sp4
-
Suse Linux Enterprise Server Version 10 sp4
-
Apple Mac Os X Version 10.8.0 Fixed in Version 10.8.2
-
Apple Mac Os X Version 10.6.8 Fixed in Version 10.7.5
-
Red Hat Enterprise Linux Server Version 5.0
-
Red Hat Enterprise Linux Workstation Version 5.0
-
Red Hat Enterprise Linux Desktop Version 6.0
-
Red Hat Enterprise Linux Server Version 6.0
-
Red Hat Enterprise Linux Workstation Version 6.0
-
Red Hat Enterprise Linux Server Aus Version 5.6
-
Red Hat Storage Version 2.0
-
Red Hat Storage For Public Cloud Version 2.0
-
Red Hat Enterprise Linux Eus Version 5.6
-
Red Hat Enterprise Linux Eus Version 6.2
-
Red Hat Enterprise Linux Eus Version 6.1
-
Red Hat Enterprise Linux Server Aus Version 5.3
-
Red Hat Gluster Storage Server On Premise Version 2.0
-
Red Hat Application Stack Version 2.0