{"api_version":"1","generated_at":"2026-07-23T11:52:44+00:00","cve":"CVE-2012-1823","urls":{"html":"https://cve.report/CVE-2012-1823","api":"https://cve.report/api/cve/CVE-2012-1823.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-1823","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-1823"},"summary":{"title":"CVE-2012-1823","description":"sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.","state":"PUBLISHED","assigner":"certcc","published_at":"2012-05-11 10:15:48","updated_at":"2026-04-21 20:28:53"},"problem_types":["CWE-77","n/a","CWE-77 CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1823","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1823","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/673343","name":"http://www.kb.cert.org/vuls/id/673343","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#673343 - Parallels Plesk Panel phppath/php vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-0570.html","name":"http://rhn.redhat.com/errata/RHSA-2012-0570.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041","name":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"HPSBMU02786 SSRT100877 rev.2 - HP System Management Homepage (SMH) Running on Linux, Windows, and VMware ESX, Remote Unauthorized Access, Disclosure of Information, Data Modification, Denial of Service (DoS), Execution of Arbitrary Code - c03360041 - \r\n\t\tHP Business Support Center","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/49085","name":"http://secunia.com/advisories/49085","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Release Notes"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.php.net/archive/2012.php#id2012-05-03-1","name":"http://www.php.net/archive/2012.php#id2012-05-03-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"PHP: News Archive - 2012","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/49014","name":"http://secunia.com/advisories/49014","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Security Alerts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/","name":"http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit"],"title":"DE EINDBAZEN » Eindbazen PHP-CGI advisory (CVE-2012-1823)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2012/dsa-2465","name":"http://www.debian.org/security/2012/dsa-2465","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-2465-1 php5","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-0569.html","name":"http://rhn.redhat.com/errata/RHSA-2012-0569.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/49065","name":"http://secunia.com/advisories/49065","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.php.net/bug.php?id=61910","name":"https://bugs.php.net/bug.php?id=61910","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"PHP :: Sec Bug #61910 :: VU#520827 - PHP-CGI query string parameter vulnerability","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-0546.html","name":"http://rhn.redhat.com/errata/RHSA-2012-0546.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:068","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support / Security / Advisories /  / MDVSA-2012:068 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00002.html","name":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2012:0590-1: critical: update for php5","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT5501","name":"http://support.apple.com/kb/HT5501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About the security content of OS X Mountain Lion v10.8.2, OS X Lion v10.7.5 and Security Update 2012-004","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00011.html","name":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00011.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2012:0604-1: critical: Security update for P","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.php.net/patch-display.php?bug_id=61910&patch=cgi.diff&revision=1335984315&display=1","name":"https://bugs.php.net/patch-display.php?bug_id=61910&patch=cgi.diff&revision=1335984315&display=1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"PHP :: Bug #61910 :: Patches","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-0568.html","name":"http://rhn.redhat.com/errata/RHSA-2012-0568.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Release Notes"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Release Notes"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=134012830914727&w=2","name":"http://marc.info/?l=bugtraq&m=134012830914727&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"'[security bulletin] HPSBUX02791 SSRT100856 rev.1 - HP-UX Apache Web Server running PHP, Remote Execu' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-0547.html","name":"http://rhn.redhat.com/errata/RHSA-2012-0547.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1027022","name":"http://www.securitytracker.com/id?1027022","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"PHP Command Parameter Bug Lets Remote Users Obtain Potentially Sensitive Information and Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.php.net/ChangeLog-5.php#5.4.2","name":"http://www.php.net/ChangeLog-5.php#5.4.2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Release Notes"],"title":"PHP: PHP 5 ChangeLog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00007.html","name":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2012:0598-1: critical: Security update for P","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/520827","name":"http://www.kb.cert.org/vuls/id/520827","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#520827 - PHP-CGI query string parameter vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/49087","name":"http://secunia.com/advisories/49087","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Security Alerts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2024/06/07/1","name":"http://www.openwall.com/lists/oss-security/2024/06/07/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","name":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"APPLE-SA-2012-09-19-2 OS X Mountain Lion v10.8.2,\tOS X Lion v10.7.5 and Security Update 2012-004","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-1823","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-1823","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[{"source":"ADP","time":"2022-03-25T00:00:00.000Z","lang":"en","value":"CVE-2012-1823 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"1823","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php","cpe5":"php","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2012","cve_id":"1823","cve":"CVE-2012-1823","vendorProject":"PHP","product":"PHP","vulnerabilityName":"PHP-CGI Query String Parameter Vulnerability","dateAdded":"2022-03-25","shortDescription":"sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-04-15","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2012-1823","cwes":"CWE-20","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:16"},"epss":{"cve_year":"2012","cve_id":"1823","cve":"CVE-2012-1823","epss":"0.999980000","percentile":"0.999890000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2025-11-04T17:11:54.860Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"SSRT100856","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=134012830914727&w=2"},{"name":"SUSE-SU-2012:0604","tags":["vendor-advisory","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00011.html"},{"name":"1027022","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id?1027022"},{"name":"HPSBMU02786","tags":["vendor-advisory","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041"},{"name":"MDVSA-2012:068","tags":["vendor-advisory","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:068"},{"name":"openSUSE-SU-2012:0590","tags":["vendor-advisory","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00002.html"},{"name":"RHSA-2012:0546","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0546.html"},{"name":"RHSA-2012:0568","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0568.html"},{"name":"RHSA-2012:0569","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0569.html"},{"tags":["x_transferred"],"url":"http://www.php.net/ChangeLog-5.php#5.4.2"},{"name":"49014","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/49014"},{"name":"RHSA-2012:0570","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0570.html"},{"name":"SUSE-SU-2012:0598","tags":["vendor-advisory","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00007.html"},{"tags":["x_transferred"],"url":"https://bugs.php.net/bug.php?id=61910"},{"name":"VU#673343","tags":["third-party-advisory","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/673343"},{"name":"RHSA-2012:0547","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0547.html"},{"name":"APPLE-SA-2012-09-19-2","tags":["vendor-advisory","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html"},{"tags":["x_transferred"],"url":"http://support.apple.com/kb/HT5501"},{"tags":["x_transferred"],"url":"http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/"},{"name":"49065","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/49065"},{"name":"VU#520827","tags":["third-party-advisory","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/520827"},{"tags":["x_transferred"],"url":"https://bugs.php.net/patch-display.php?bug_id=61910&patch=cgi.diff&revision=1335984315&display=1"},{"name":"SSRT100877","tags":["vendor-advisory","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041"},{"name":"HPSBUX02791","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=134012830914727&w=2"},{"name":"DSA-2465","tags":["vendor-advisory","x_transferred"],"url":"http://www.debian.org/security/2012/dsa-2465"},{"name":"49085","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/49085"},{"tags":["x_transferred"],"url":"http://www.php.net/archive/2012.php#id2012-05-03-1"},{"name":"49087","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/49087"},{"name":"[oss-security] 20240606 PHP security releases 8.3.8, 8.2.20, and 8.1.29","tags":["mailing-list","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2024/06/07/1"},{"name":"FEDORA-2024-49aba7b305","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"},{"name":"FEDORA-2024-52c23ef1ec","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2012-1823","options":[{"Exploitation":"active"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-02-07T13:10:55.600294Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2022-03-25","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1823"},"type":"kev"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-77","description":"CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-22T00:05:47.580Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-1823"}],"timeline":[{"lang":"en","time":"2022-03-25T00:00:00.000Z","value":"CVE-2012-1823 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-05-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2024-06-13T04:06:14.603Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"SSRT100856","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=134012830914727&w=2"},{"name":"SUSE-SU-2012:0604","tags":["vendor-advisory"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00011.html"},{"name":"1027022","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id?1027022"},{"name":"HPSBMU02786","tags":["vendor-advisory"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041"},{"name":"MDVSA-2012:068","tags":["vendor-advisory"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2012:068"},{"name":"openSUSE-SU-2012:0590","tags":["vendor-advisory"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00002.html"},{"name":"RHSA-2012:0546","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0546.html"},{"name":"RHSA-2012:0568","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0568.html"},{"name":"RHSA-2012:0569","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0569.html"},{"url":"http://www.php.net/ChangeLog-5.php#5.4.2"},{"name":"49014","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/49014"},{"name":"RHSA-2012:0570","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0570.html"},{"name":"SUSE-SU-2012:0598","tags":["vendor-advisory"],"url":"http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00007.html"},{"url":"https://bugs.php.net/bug.php?id=61910"},{"name":"VU#673343","tags":["third-party-advisory"],"url":"http://www.kb.cert.org/vuls/id/673343"},{"name":"RHSA-2012:0547","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2012-0547.html"},{"name":"APPLE-SA-2012-09-19-2","tags":["vendor-advisory"],"url":"http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html"},{"url":"http://support.apple.com/kb/HT5501"},{"url":"http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/"},{"name":"49065","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/49065"},{"name":"VU#520827","tags":["third-party-advisory"],"url":"http://www.kb.cert.org/vuls/id/520827"},{"url":"https://bugs.php.net/patch-display.php?bug_id=61910&patch=cgi.diff&revision=1335984315&display=1"},{"name":"SSRT100877","tags":["vendor-advisory"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041"},{"name":"HPSBUX02791","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=134012830914727&w=2"},{"name":"DSA-2465","tags":["vendor-advisory"],"url":"http://www.debian.org/security/2012/dsa-2465"},{"name":"49085","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/49085"},{"url":"http://www.php.net/archive/2012.php#id2012-05-03-1"},{"name":"49087","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/49087"},{"name":"[oss-security] 20240606 PHP security releases 8.3.8, 8.2.20, and 8.1.29","tags":["mailing-list"],"url":"http://www.openwall.com/lists/oss-security/2024/06/07/1"},{"name":"FEDORA-2024-49aba7b305","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/"},{"name":"FEDORA-2024-52c23ef1ec","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/"}]}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2012-1823","datePublished":"2012-05-11T10:00:00.000Z","dateReserved":"2012-03-21T00:00:00.000Z","dateUpdated":"2025-11-04T17:11:54.860Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2012-05-11 10:15:48","lastModifiedDate":"2026-04-21 20:28:53","problem_types":["CWE-77","n/a","CWE-77 CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionEndExcluding":"5.3.12","matchCriteriaId":"B7565237-10C7-44C5-BFA0-24C84E7B10C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.0","versionEndExcluding":"5.4.2","matchCriteriaId":"2E2DD924-DBE9-438D-B5D9-60840046CA08"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*","matchCriteriaId":"B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*","matchCriteriaId":"CA277A6C-83EC-4536-9125-97B84C4FAF59"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*","matchCriteriaId":"036E8A89-7A16-411F-9D31-676313BB7244"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:hp:hp-ux:b.11.23:*:*:*:*:*:*:*","matchCriteriaId":"12C73959-3E02-4847-8962-651D652800EE"},{"vulnerable":true,"criteria":"cpe:2.3:o:hp:hp-ux:b.11.31:*:*:*:*:*:*:*","matchCriteriaId":"B64BBA96-FB3C-46AC-9A29-50EE02714FE9"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*","matchCriteriaId":"DE554781-1EB9-446E-911F-6C11970C47F4"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*","matchCriteriaId":"EBB2C482-D2A4-48B3-ACE7-E1DFDCC409B5"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*","matchCriteriaId":"D1D7B467-58DD-45F1-9F1F-632620DF072A"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*","matchCriteriaId":"88D6E858-FD8F-4C55-B7D5-CEEDA2BBA898"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*","matchCriteriaId":"DB4D6749-81A1-41D7-BF4F-1C45A7F49A22"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*","matchCriteriaId":"436EF2ED-FDBB-4B64-8EC4-33C3E4253F06"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp2:*:*:*:*:*:*","matchCriteriaId":"5AA37837-3083-4DC7-94F4-54FD5D7CB53C"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","versionStartIncluding":"10.6.8","versionEndExcluding":"10.7.5","matchCriteriaId":"BF149F33-4D3B-4252-8D96-AB912B2DEB43"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"10.8.2","matchCriteriaId":"283B3DF2-DAFA-4333-B3CF-181ACD635137"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:application_stack:2.0:*:*:*:*:*:*:*","matchCriteriaId":"847A353B-833B-4A2A-8B87-2C6BA88A8CC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.0:*:*:*:*:*:*:*","matchCriteriaId":"59D47E43-886E-4114-96A2-DBE719EA3A89"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:storage:2.0:*:*:*:*:*:*:*","matchCriteriaId":"52B90A04-DD6D-4AE7-A0E5-6B381127D507"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:storage_for_public_cloud:2.0:*:*:*:*:*:*:*","matchCriteriaId":"F0257753-51C3-45F2-BAA4-4C1F2DEAB7A6"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*","matchCriteriaId":"EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_eus:5.6:*:*:*:*:*:*:*","matchCriteriaId":"903512FC-0017-4564-9B89-7E64FFB14B11"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_eus:6.1:*:*:*:*:*:*:*","matchCriteriaId":"3BEEC943-452C-4A19-B492-5EC8ADE427CD"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_eus:6.2:*:*:*:*:*:*:*","matchCriteriaId":"C0554C89-3716-49F3-BFAE-E008D5E4E29C"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*","matchCriteriaId":"54D669D4-6D7E-449D-80C1-28FA44F06FFE"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"9BBCD86A-E6C7-4444-9D74-F861084090F0"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server_aus:5.3:*:*:*:*:*:*:*","matchCriteriaId":"1F87B994-28E4-4095-8770-6433DE9C93AB"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_server_aus:5.6:*:*:*:*:*:*:*","matchCriteriaId":"BB6ADFB8-210D-4E46-82A2-1C8705928382"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*","matchCriteriaId":"D0AC5CD5-6E58-433C-9EB3-6DFE5656463E"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*","matchCriteriaId":"E5ED5807-55B7-47C5-97A6-03233F4FBC3A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"1823","Ordinal":"1","Title":"CVE-2012-1823","CVE":"CVE-2012-1823","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"1823","Ordinal":"1","NoteData":"sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.","Type":"Description","Title":"CVE-2012-1823"},{"CveYear":"2012","CveId":"1823","Ordinal":"2","NoteData":"2012-05-11","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"1823","Ordinal":"3","NoteData":"2018-01-17","Type":"Other","Title":"Modified"}]}}}