CVE-2012-0831
php: PG(magic_quote_gpc) was not restored on shutdown
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.
PHP anterior a v5.3.10 no realizan de forma adecuada un cambio temporal a la directiva magic_quotes_gpc durante la importación de variables de entorno, lo que simplifica a atacantes remotos conducir ataques de inyección SQL a través de peticiones manipuladaas, relacionado con main/php_variables.c, sapi/cgi/cgi_main.c, y sapi/fpm/fpm/fpm_main.c.
PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. It was found that PHP did not properly handle file names with a NULL character. A remote attacker could possibly use this flaw to make a PHP script access unexpected files and bypass intended file system access restrictions. It was found that PHP did not check for carriage returns in HTTP headers, allowing intended HTTP response splitting protections to be bypassed. Depending on the web browser the victim is using, a remote attacker could use this flaw to perform HTTP response splitting attacks.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-01-19 CVE Reserved
- 2012-02-10 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-04-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/48668 | Third Party Advisory | |
http://secunia.com/advisories/55078 | Third Party Advisory | |
http://support.apple.com/kb/HT5501 | Third Party Advisory |
|
https://exchange.xforce.ibmcloud.com/vulnerabilities/73125 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://launchpadlibrarian.net/92454212/php5_5.3.2-1ubuntu4.13.diff.gz | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/51954 | 2022-08-16 | |
http://www.ubuntu.com/usn/USN-1358-1 | 2022-08-16 |