Evidence dossier

CVE-2012-1823

CVE-2012-1823

78.799.5Priority evidence range
As known Jul 21, 2026, 8:13 AM UTCgen-409cbd0c

Normalized restatement

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

State
PUBLISHED
Published
May 11, 2012
Updated
Nov 4, 2025
Evidence coverage
72%
CISA KEVCatalog member

Apply updates per vendor instructions.

FIRST EPSS100.00%

2026-07-18 · v2026.06.15 · percentile 100.0%

Source stateConflict visible

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

certccoriginal assertion
container

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

CISA KEVoriginal assertion
observed_exploitation

PHP-CGI Query String Parameter Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.999980000000; percentile 0.999890000000

Applicability

Cited product scope

Trace impact →
30Underlying assertions
17Canonical products
30Target assertions
0Constraint assertions

Grouped from 7 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.

Identity source boundaries
  • cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

18 scope groups

certcc · source assertedn/an/aDirect source scope
[{"status": "affected", "version": "n/a"}]
unknown
NVD CPE · OPERATING SYSTEMapplemac_os_xVulnerable target · 2 assertions
Any version (unconstrained) (>= 10.6.8, < 10.7.5); Any version (unconstrained) (>= 10.8.0, < 10.8.2)Canonical identity product-94613e1f5039e71a9805f20421d56ac6a61e2707d3f97a08fdf6823a65dc7b76linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 10.8.0; through excluding 10.8.2
    Match ID
    283b3df2-dafa-4333-b3cf-181acd635137
  2. cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 10.6.8; through excluding 10.7.5
    Match ID
    bf149f33-4d3b-4252-8d96-ab912b2deb43
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 1 assertions
Version 6.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447elinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    036e8a89-7a16-411f-9d31-676313bb7244
NVD CPE · OPERATING SYSTEMfedoraprojectfedoraVulnerable target · 2 assertions
Version 39; Version 40Canonical identity product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b8edb836-4e6a-4b71-b9b2-aa3e03e0f646
  2. cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ca277a6c-83ec-4536-9125-97b84c4faf59
NVD CPE · OPERATING SYSTEMhphp-uxVulnerable target · 2 assertions
Version b.11.23; Version b.11.31Canonical identity product-0e113084e98722ecb2bd0dad810b56a8414556ee39cd5f91cadcaff5e7f19145linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:hp:hp-ux:b.11.23:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    12c73959-3e02-4847-8962-651d652800ee
  2. cpe:2.3:o:hp:hp-ux:b.11.31:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b64bba96-fb3c-46ac-9a29-50ee02714fe9
NVD CPE · OPERATING SYSTEMopensuseopensuseVulnerable target · 2 assertions
Version 11.4; Version 12.1Canonical identity product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bdlinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    de554781-1eb9-446e-911f-6c11970c47f4
  2. cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ebb2c482-d2a4-48b3-ace7-e1dfdcc409b5
NVD CPE · APPLICATIONphpphpVulnerable target · 2 assertions
Any version (unconstrained) (< 5.3.12); Any version (unconstrained) (>= 5.4.0, < 5.4.2)Canonical identity product-e6438e3fdd6f4fab833b9e95f3122542080fe89ddf2636dd7eb83d66f8118f15linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 5.3.12
    Match ID
    b7565237-10c7-44c5-bfa0-24c84e7b10c3
  2. cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 5.4.0; through excluding 5.4.2
    Match ID
    2e2dd924-dbe9-438d-b5d9-60840046ca08
NVD CPE · APPLICATIONredhatapplication_stackVulnerable target · 1 assertions
Version 2.0Canonical identity product-590b17d48a87cd8bd01cf220aa29aee1d87ef9ca8eb9e880efbd8df7bbea4bdblinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:redhat:application_stack:2.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    847a353b-833b-4a2a-8b87-2c6ba88a8cc8
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_desktopVulnerable target · 1 assertions
Version 6.0Canonical identity product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aelinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eusVulnerable target · 3 assertions
Version 5.6; Version 6.1; Version 6.2Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378linked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_eus:6.1:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3beec943-452c-4a19-b492-5ec8ade427cd
  2. cpe:2.3:o:redhat:enterprise_linux_eus:5.6:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    903512fc-0017-4564-9b89-7e64ffb14b11
  3. cpe:2.3:o:redhat:enterprise_linux_eus:6.2:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c0554c89-3716-49f3-bfae-e008d5e4e29c
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_serverVulnerable target · 2 assertions
Version 5.0; Version 6.0Canonical identity product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dealinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9bbcd86a-e6c7-4444-9d74-f861084090f0
  2. cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    54d669d4-6d7e-449d-80c1-28fa44f06ffe
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_ausVulnerable target · 2 assertions
Version 5.3; Version 5.6Canonical identity product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaelinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_aus:5.3:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1f87b994-28e4-4095-8770-6433de9c93ab
  2. cpe:2.3:o:redhat:enterprise_linux_server_aus:5.6:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb6adfb8-210d-4e46-82a2-1c8705928382
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_workstationVulnerable target · 2 assertions
Version 5.0; Version 6.0Canonical identity product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9linked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0ac5cd5-6e58-433c-9eb3-6dfe5656463e
  2. cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5ed5807-55b7-47c5-97a6-03233f4fbc3a
NVD CPE · APPLICATIONredhatgluster_storage_server_for_on-premiseVulnerable target · 1 assertions
Version 2.0Canonical identity product-5fb86209cb28a171a615b064839fb8a647f4262a91b6043cb733d29a3026f76elinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    59d47e43-886e-4114-96a2-dbe719ea3a89
NVD CPE · APPLICATIONredhatstorageVulnerable target · 1 assertions
Version 2.0Canonical identity product-c6ae95e309497ada4c1889e6d03b86bd52986c56a51129f0b89bc25e3be2097clinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:redhat:storage:2.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52b90a04-dd6d-4ae7-a0e5-6b381127d507
NVD CPE · APPLICATIONredhatstorage_for_public_cloudVulnerable target · 1 assertions
Version 2.0Canonical identity product-f361d0d92654b5e2de70df275614700a64db37e58d08b8dea7fe42bedafa987clinked exact
supported
Inspect 1 returned assertions
  1. cpe:2.3:a:redhat:storage_for_public_cloud:2.0:*:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f0257753-51c3-45f2-baa4-4c1f2deab7a6
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_serverVulnerable target · 3 assertions
Version 10; Version 11Canonical identity product-4f2240e45c4385f8980643ce838561b90551012dc317022ee66a7d71a9db8e28linked exact
supported
Inspect 3 returned assertions
  1. cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1d7b467-58dd-45f1-9f1f-632620df072a
  2. cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88d6e858-fd8f-4c55-b7d5-ceeda2bba898
  3. cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db4d6749-81a1-41d7-bf4f-1c45a7f49a22
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_software_development_kitVulnerable target · 2 assertions
Version 10; Version 11Canonical identity product-bd4950335ff1f3f03b9dd6fa5c596f7c67c9ea6d150272de074ec3767af3532alinked exact
supported
Inspect 2 returned assertions
  1. cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp2:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5aa37837-3083-4dc7-94f4-54fd5d7cb53c
  2. cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*
    Official link
    linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    436ef2ed-fdbb-4b64-8ec4-33c3e4253f06

Assessments

CVSS by origin

7.5
nvd@nist.govCVSS 2.0 · role PrimaryAV:N/AC:L/Au:N/C:P/I:P/A:P
9.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.