7.5

CVE-2012-2311

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpPhp Version <= 5.3.12
   PhpPhp Version <= 5.3.12
PhpPhp Version1.0
   PhpPhp Version1.0
PhpPhp Version2.0
   PhpPhp Version2.0
PhpPhp Version2.0b10
   PhpPhp Version2.0b10
PhpPhp Version3.0
   PhpPhp Version3.0
PhpPhp Version3.0.1
   PhpPhp Version3.0.1
PhpPhp Version3.0.2
   PhpPhp Version3.0.2
PhpPhp Version3.0.3
   PhpPhp Version3.0.3
PhpPhp Version3.0.4
   PhpPhp Version3.0.4
PhpPhp Version3.0.5
   PhpPhp Version3.0.5
PhpPhp Version3.0.6
   PhpPhp Version3.0.6
PhpPhp Version3.0.7
   PhpPhp Version3.0.7
PhpPhp Version3.0.8
   PhpPhp Version3.0.8
PhpPhp Version3.0.9
   PhpPhp Version3.0.9
PhpPhp Version3.0.10
   PhpPhp Version3.0.10
PhpPhp Version3.0.11
   PhpPhp Version3.0.11
PhpPhp Version3.0.12
   PhpPhp Version3.0.12
PhpPhp Version3.0.13
   PhpPhp Version3.0.13
PhpPhp Version3.0.14
   PhpPhp Version3.0.14
PhpPhp Version3.0.15
   PhpPhp Version3.0.15
PhpPhp Version3.0.16
   PhpPhp Version3.0.16
PhpPhp Version3.0.17
   PhpPhp Version3.0.17
PhpPhp Version3.0.18
   PhpPhp Version3.0.18
PhpPhp Version4.0 Updatebeta_4_patch1
   PhpPhp Version4.0 Updatebeta_4_patch1
PhpPhp Version4.0 Updatebeta1
   PhpPhp Version4.0 Updatebeta1
PhpPhp Version4.0 Updatebeta2
   PhpPhp Version4.0 Updatebeta2
PhpPhp Version4.0 Updatebeta3
   PhpPhp Version4.0 Updatebeta3
PhpPhp Version4.0 Updatebeta4
   PhpPhp Version4.0 Updatebeta4
PhpPhp Version4.0.0
   PhpPhp Version4.0.0
PhpPhp Version4.0.1
   PhpPhp Version4.0.1
PhpPhp Version4.0.2
   PhpPhp Version4.0.2
PhpPhp Version4.0.3
   PhpPhp Version4.0.3
PhpPhp Version4.0.4
   PhpPhp Version4.0.4
PhpPhp Version4.0.5
   PhpPhp Version4.0.5
PhpPhp Version4.0.6
   PhpPhp Version4.0.6
PhpPhp Version4.0.7
   PhpPhp Version4.0.7
PhpPhp Version4.1.0
   PhpPhp Version4.1.0
PhpPhp Version4.1.1
   PhpPhp Version4.1.1
PhpPhp Version4.1.2
   PhpPhp Version4.1.2
PhpPhp Version4.2.0
   PhpPhp Version4.2.0
PhpPhp Version4.2.1
   PhpPhp Version4.2.1
PhpPhp Version4.2.2
   PhpPhp Version4.2.2
PhpPhp Version4.2.3
   PhpPhp Version4.2.3
PhpPhp Version4.3.0
   PhpPhp Version4.3.0
PhpPhp Version4.3.1
   PhpPhp Version4.3.1
PhpPhp Version4.3.2
   PhpPhp Version4.3.2
PhpPhp Version4.3.3
   PhpPhp Version4.3.3
PhpPhp Version4.3.4
   PhpPhp Version4.3.4
PhpPhp Version4.3.5
   PhpPhp Version4.3.5
PhpPhp Version4.3.6
   PhpPhp Version4.3.6
PhpPhp Version4.3.7
   PhpPhp Version4.3.7
PhpPhp Version4.3.8
   PhpPhp Version4.3.8
PhpPhp Version4.3.9
   PhpPhp Version4.3.9
PhpPhp Version4.3.10
   PhpPhp Version4.3.10
PhpPhp Version4.3.11
   PhpPhp Version4.3.11
PhpPhp Version4.4.0
   PhpPhp Version4.4.0
PhpPhp Version4.4.1
   PhpPhp Version4.4.1
PhpPhp Version4.4.2
   PhpPhp Version4.4.2
PhpPhp Version4.4.3
   PhpPhp Version4.4.3
PhpPhp Version4.4.4
   PhpPhp Version4.4.4
PhpPhp Version4.4.5
   PhpPhp Version4.4.5
PhpPhp Version4.4.6
   PhpPhp Version4.4.6
PhpPhp Version4.4.7
   PhpPhp Version4.4.7
PhpPhp Version4.4.8
   PhpPhp Version4.4.8
PhpPhp Version4.4.9
   PhpPhp Version4.4.9
PhpPhp Version5.0.0
   PhpPhp Version5.0.0
PhpPhp Version5.0.0 Updatebeta1
   PhpPhp Version5.0.0 Updatebeta1
PhpPhp Version5.0.0 Updatebeta2
   PhpPhp Version5.0.0 Updatebeta2
PhpPhp Version5.0.0 Updatebeta3
   PhpPhp Version5.0.0 Updatebeta3
PhpPhp Version5.0.0 Updatebeta4
   PhpPhp Version5.0.0 Updatebeta4
PhpPhp Version5.0.0 Updaterc1
   PhpPhp Version5.0.0 Updaterc1
PhpPhp Version5.0.0 Updaterc2
   PhpPhp Version5.0.0 Updaterc2
PhpPhp Version5.0.0 Updaterc3
   PhpPhp Version5.0.0 Updaterc3
PhpPhp Version5.0.1
   PhpPhp Version5.0.1
PhpPhp Version5.0.2
   PhpPhp Version5.0.2
PhpPhp Version5.0.3
   PhpPhp Version5.0.3
PhpPhp Version5.0.4
   PhpPhp Version5.0.4
PhpPhp Version5.0.5
   PhpPhp Version5.0.5
PhpPhp Version5.1.0
   PhpPhp Version5.1.0
PhpPhp Version5.1.1
   PhpPhp Version5.1.1
PhpPhp Version5.1.2
   PhpPhp Version5.1.2
PhpPhp Version5.1.3
   PhpPhp Version5.1.3
PhpPhp Version5.1.4
   PhpPhp Version5.1.4
PhpPhp Version5.1.5
   PhpPhp Version5.1.5
PhpPhp Version5.1.6
   PhpPhp Version5.1.6
PhpPhp Version5.2.0
   PhpPhp Version5.2.0
PhpPhp Version5.2.1
   PhpPhp Version5.2.1
PhpPhp Version5.2.2
   PhpPhp Version5.2.2
PhpPhp Version5.2.3
   PhpPhp Version5.2.3
PhpPhp Version5.2.4
   PhpPhp Version5.2.4
PhpPhp Version5.2.5
   PhpPhp Version5.2.5
PhpPhp Version5.2.6
   PhpPhp Version5.2.6
PhpPhp Version5.2.7
   PhpPhp Version5.2.7
PhpPhp Version5.2.8
   PhpPhp Version5.2.8
PhpPhp Version5.2.9
   PhpPhp Version5.2.9
PhpPhp Version5.2.10
   PhpPhp Version5.2.10
PhpPhp Version5.2.11
   PhpPhp Version5.2.11
PhpPhp Version5.2.12
   PhpPhp Version5.2.12
PhpPhp Version5.2.13
   PhpPhp Version5.2.13
PhpPhp Version5.2.14
   PhpPhp Version5.2.14
PhpPhp Version5.2.15
   PhpPhp Version5.2.15
PhpPhp Version5.2.16
   PhpPhp Version5.2.16
PhpPhp Version5.2.17
   PhpPhp Version5.2.17
PhpPhp Version5.3.0
   PhpPhp Version5.3.0
PhpPhp Version5.3.1
   PhpPhp Version5.3.1
PhpPhp Version5.3.2
   PhpPhp Version5.3.2
PhpPhp Version5.3.3
   PhpPhp Version5.3.3
PhpPhp Version5.3.4
   PhpPhp Version5.3.4
PhpPhp Version5.3.5
   PhpPhp Version5.3.5
PhpPhp Version5.3.6
   PhpPhp Version5.3.6
PhpPhp Version5.3.7
   PhpPhp Version5.3.7
PhpPhp Version5.3.8
   PhpPhp Version5.3.8
PhpPhp Version5.3.9
   PhpPhp Version5.3.9
PhpPhp Version5.3.10
   PhpPhp Version5.3.10
PhpPhp Version5.3.11
   PhpPhp Version5.3.11
PhpPhp Version5.4.0
   PhpPhp Version5.4.0
PhpPhp Version5.4.0 Updatebeta2
   PhpPhp Version5.4.0 Updatebeta2
PhpPhp Version5.4.1
   PhpPhp Version5.4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.96% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.