Web1 vuln-feed

Finding #9 — CVE-2012-1823

Inventory item php-test 8.3.31 (software, php)
TitlePHP Group PHP: PHP-CGI OS Command Injection Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:11Z
Last updated2026-06-11T07:35:11Z
CVECVE-2012-1823 KEV since 2022-03-25
CVSSnot enriched yet (pending)
Descriptionsapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
Source advisoryPHP Group PHP: PHP-CGI OS Command Injection Vulnerability
PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

Update status