CVE-2012-0830: PHP

High severity, CVSS 7.5. EPSS: 29.8% chance of exploitation in the next 30 days.

The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.

Affected products

  • PHP PHP: version 5.3.9 only

Published 2012-02-06. Last modified 2026-06-16.