CVE-2012-0831
php: PG(magic_quote_gpc) was not restored on shutdown
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.
PHP anterior a v5.3.10 no realizan de forma adecuada un cambio temporal a la directiva magic_quotes_gpc durante la importación de variables de entorno, lo que simplifica a atacantes remotos conducir ataques de inyección SQL a través de peticiones manipuladaas, relacionado con main/php_variables.c, sapi/cgi/cgi_main.c, y sapi/fpm/fpm/fpm_main.c.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-01-19 CVE Reserved
- 2012-02-10 CVE Published
- 2023-11-09 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/48668 | Third Party Advisory | |
http://secunia.com/advisories/55078 | Third Party Advisory | |
http://support.apple.com/kb/HT5501 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/73125 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://launchpadlibrarian.net/92454212/php5_5.3.2-1ubuntu4.13.diff.gz | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/51954 | 2022-08-16 | |
http://www.ubuntu.com/usn/USN-1358-1 | 2022-08-16 |