Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2012-1823

Quick assessment

Affected
n/a n/a
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 PHP中存在信息泄漏漏洞。远程攻击者可利用该漏洞在服务器进程上下文中查看文件的源代码,获取敏感信息,在受影响计算机上运行任意PHP代码,也可能执行其他攻击。

AI Predicted 9.8 Difficulty: Easy KEV EPSS 100.00% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2012-1823

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
PHP ‘php-cgi’ 参数信息泄漏漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 PHP中存在信息泄漏漏洞。远程攻击者可利用该漏洞在服务器进程上下文中查看文件的源代码,获取敏感信息,在受影响计算机上运行任意PHP代码,也可能执行其他攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2012-1823

# POC Description Source Link Shenlong Link
1 None https://github.com/drone789/CVE-2012-1823 POC Details
2 First script, pgp-cgi-cve-2012-1823 BASH script https://github.com/tardummy01/oscp_scripts-1 POC Details
3 PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured NFS files, etc. https://github.com/Unix13/metasploitable2 POC Details
4 None https://github.com/cyberharsh/PHP_CVE-2012-1823 POC Details
5 PHP CGI Argument Injection RCE https://github.com/theykillmeslowly/CVE-2012-1823 POC Details
6 PHP CGI Argument Injection. https://github.com/0xl0k1/CVE-2012-1823 POC Details
7 Prova de conceito para PHP CGI Argument Injection (CVE-2012-1823) https://github.com/Fatalitysec/CVE-2012-1823 POC Details
8 Prova de conceito de PHP CGI Argument Injection. https://github.com/Fatalityx84/CVE-2012-1823 POC Details
9 Prova de conceito de php cgi argument injection https://github.com/0xFatality/CVE-2012-1823 POC Details
10 None https://github.com/Jimmy01240397/CVE-2012-1823-Analyze POC Details
11 CVE-2012-1823 exploit for https user password website. https://github.com/JasonHobs/CVE-2012-1823-exploit-for-https-user-password-web POC Details
12 sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2012/CVE-2012-1823.yaml POC Details
13 None https://github.com/chaitin/xray-plugins/blob/main/poc/manual/php-cgi-cve-2012-1823.yml POC Details
14 https://github.com/vulhub/vulhub/blob/master/php/CVE-2012-1823/README.md POC Details
15 CVE-2012-1823 exploit for https user password website. https://github.com/Dmitri131313/CVE-2012-1823-exploit-for-https-user-password-web POC Details
16 Ushbu videoda Kali Linux orqali Metasploitable 2 serveriga PHP CGI Argument Injection (CVE-2012-1823) ekspluatatsiyasi Metasploit yordamida amalga oshiriladi https://github.com/nulltrace1336/PHP-CGI-Argument-Injection-Exploit POC Details
17 Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution (CVE-2012-1823). https://github.com/waburig/Open-Worldwide-Application-Security-Project-OWASP- POC Details
18 A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823. https://github.com/hackherMind-Pixel/Vulnerable-Lab-Exploitation POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-1823

请登录查看更多情报信息。

Vendor Advisories for CVE-2012-1823 (14)

Mailing List Discussions for CVE-2012-1823 (8)

Other References for CVE-2012-1823 (6)

Same Patch Batch · n/a · 2012-05-11 · 19 CVEs total

CVE-2012-0656 Apple Mac OS X ‘LoginUIFramework’ 竞争条件漏洞
CVE-2012-0676 Apple Safari ‘WebKit’ 输入验证漏洞
CVE-2012-0675 Apple Mac OS X ‘Time Machine’ 授权问题漏洞
CVE-2012-0662 Apple Mac OS X ‘Security Framework’ 整数溢出漏洞
CVE-2012-0661 Apple Mac OS X ‘QuickTime’ 释放后使用漏洞
CVE-2012-0660 Apple Mac OS X ‘QuickTime’ 缓冲区溢出漏洞
CVE-2012-0659 Apple Mac OS X ‘QuickTime’ 整数溢出漏洞
CVE-2012-0658 Apple Mac OS X ‘QuickTime’ 缓冲区溢出漏洞
CVE-2012-0657 Apple Mac OS X ‘Quartz Composer’ 权限许可和访问控制漏洞
CVE-2012-2311 PHP SQL注入漏洞
CVE-2012-0655 Apple Mac OS X ‘libsecurity’ 加密问题漏洞
CVE-2012-0654 Apple Mac OS X ‘libsecurity’ 缓冲区溢出漏洞
CVE-2012-0652 Apple Mac OS X ‘Login Window’ 信息泄露漏洞
CVE-2012-0651 Apple Mac OS X ‘Directory Service’ 信息泄露漏洞
CVE-2012-0649 Apple Mac OS X ‘blued’ 竞争条件漏洞
CVE-2012-2336 PHP 输入验证错误漏洞
CVE-2012-2335 PHP ‘php-wrapper.fcgi’ 权限许可和访问控制问题漏洞
CVE-2012-2329 PHP ‘apache_request_headers’ 函数缓冲区溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2012-1823

No comments yet


Leave a comment