CVE-2012-1823: PHP-CGI Query String Parameter Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 100% chance of exploitation in the next 30 days.

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

Affected products

  • Apple Mac OS X: from 10.6.8, before 10.7.5 (fixed in 10.7.5); from 10.8.0, before 10.8.2 (fixed in 10.8.2)
  • Debian Debian Linux: version 6.0 only
  • Fedoraproject Fedora: version 39 only; version 40 only
  • HP HP-Ux: version b.11.23 only; version b.11.31 only
  • Opensuse Opensuse: version 11.4 only; version 12.1 only
  • PHP PHP: before 5.3.12 (fixed in 5.3.12); from 5.4.0, before 5.4.2 (fixed in 5.4.2)
  • Red Hat Application Stack: version 2.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 5.6 only; version 6.1 only; version 6.2 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 5.3 only; version 5.6 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
  • Red Hat Gluster Storage Server For On-Premise: version 2.0 only
  • Red Hat Storage: version 2.0 only
  • Red Hat Storage For Public Cloud: version 2.0 only
  • Suse Linux Enterprise Server: version 10 only; version 11 only
  • Suse Linux Enterprise Software Development Kit: version 10 only; version 11 only

Published 2012-05-11. Last modified 2026-06-16.