---
cve: "CVE-2012-1823"
severity: "CRITICAL"
cvss: 9.8
epss: "100%"
vendor: "n/a"
kev: true
exploited: true
published: "2012-05-11 10:15:48"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T21:10:54+02:00"
---

# CVE-2012-1823

> 9.8 CRITICAL · ⚠️ CISA KEV (1631 Tage) · 🔓 Exploited

## Beschreibung

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Exploit-Evidenz

- [EDB-29290 — Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution](https://www.exploit-db.com/exploits/29290) ✅
- [EDB-18836 — PHP < 5.3.12 / < 5.4.2 - CGI Argument Injection](https://www.exploit-db.com/exploits/18836) ✅
- [EDB-18834 — PHP 5.3.12/5.4.2 - CGI Argument Injection (Metasploit)](https://www.exploit-db.com/exploits/18834) ✅
- [EDB-29316 — Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner](https://www.exploit-db.com/exploits/29316)

## Referenzen

- <http://marc.info/?l=bugtraq&m=134012830914727&w=2>
- <http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00011.html>
- <http://www.securitytracker.com/id?1027022>
- <http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2012:068>
- <http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00002.html>
- <http://rhn.redhat.com/errata/RHSA-2012-0546.html>
- <http://rhn.redhat.com/errata/RHSA-2012-0568.html>
- <http://rhn.redhat.com/errata/RHSA-2012-0569.html>
- <http://www.php.net/ChangeLog-5.php#5.4.2>
- <http://secunia.com/advisories/49014>
- <http://rhn.redhat.com/errata/RHSA-2012-0570.html>
- <http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00007.html>
- <https://bugs.php.net/bug.php?id=61910>
- <http://www.kb.cert.org/vuls/id/673343>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2012-1823) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
