Apply updates per vendor instructions.
Evidence dossier
CVE-2012-1823
CVE-2012-1823
gen-409cbd0cNormalized restatement
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
- State
- PUBLISHED
- Published
- May 11, 2012
- Updated
- Nov 4, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 100.0%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
PHP-CGI Query String Parameter Vulnerability
Probability 0.999980000000; percentile 0.999890000000
Applicability
Cited product scope
Grouped from 7 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.
Identity source boundaries
- cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
18 scope groups
[{"status": "affected", "version": "n/a"}]Any version (unconstrained) (>= 10.6.8, < 10.7.5); Any version (unconstrained) (>= 10.8.0, < 10.8.2)Canonical identity product-94613e1f5039e71a9805f20421d56ac6a61e2707d3f97a08fdf6823a65dc7b76linked exactInspect 2 returned assertions
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 10.8.0; through excluding 10.8.2
- Match ID
283b3df2-dafa-4333-b3cf-181acd635137
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 10.6.8; through excluding 10.7.5
- Match ID
bf149f33-4d3b-4252-8d96-ab912b2deb43
Version 6.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447elinked exactInspect 1 returned assertions
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
036e8a89-7a16-411f-9d31-676313bb7244
Version 39; Version 40Canonical identity product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47linked exactInspect 2 returned assertions
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b8edb836-4e6a-4b71-b9b2-aa3e03e0f646
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ca277a6c-83ec-4536-9125-97b84c4faf59
Version b.11.23; Version b.11.31Canonical identity product-0e113084e98722ecb2bd0dad810b56a8414556ee39cd5f91cadcaff5e7f19145linked exactInspect 2 returned assertions
cpe:2.3:o:hp:hp-ux:b.11.23:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
12c73959-3e02-4847-8962-651d652800ee
cpe:2.3:o:hp:hp-ux:b.11.31:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b64bba96-fb3c-46ac-9a29-50ee02714fe9
Version 11.4; Version 12.1Canonical identity product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bdlinked exactInspect 2 returned assertions
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
de554781-1eb9-446e-911f-6c11970c47f4
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ebb2c482-d2a4-48b3-ace7-e1dfdcc409b5
Any version (unconstrained) (< 5.3.12); Any version (unconstrained) (>= 5.4.0, < 5.4.2)Canonical identity product-e6438e3fdd6f4fab833b9e95f3122542080fe89ddf2636dd7eb83d66f8118f15linked exactInspect 2 returned assertions
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 5.3.12
- Match ID
b7565237-10c7-44c5-bfa0-24c84e7b10c3
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 5.4.0; through excluding 5.4.2
- Match ID
2e2dd924-dbe9-438d-b5d9-60840046ca08
Version 2.0Canonical identity product-590b17d48a87cd8bd01cf220aa29aee1d87ef9ca8eb9e880efbd8df7bbea4bdblinked exactInspect 1 returned assertions
cpe:2.3:a:redhat:application_stack:2.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
847a353b-833b-4a2a-8b87-2c6ba88a8cc8
Version 6.0Canonical identity product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aelinked exactInspect 1 returned assertions
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
Version 5.6; Version 6.1; Version 6.2Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378linked exactInspect 3 returned assertions
cpe:2.3:o:redhat:enterprise_linux_eus:6.1:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3beec943-452c-4a19-b492-5ec8ade427cd
cpe:2.3:o:redhat:enterprise_linux_eus:5.6:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
903512fc-0017-4564-9b89-7e64ffb14b11
cpe:2.3:o:redhat:enterprise_linux_eus:6.2:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c0554c89-3716-49f3-bfae-e008d5e4e29c
Version 5.0; Version 6.0Canonical identity product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dealinked exactInspect 2 returned assertions
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9bbcd86a-e6c7-4444-9d74-f861084090f0
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
54d669d4-6d7e-449d-80c1-28fa44f06ffe
Version 5.3; Version 5.6Canonical identity product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaelinked exactInspect 2 returned assertions
cpe:2.3:o:redhat:enterprise_linux_server_aus:5.3:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1f87b994-28e4-4095-8770-6433de9c93ab
cpe:2.3:o:redhat:enterprise_linux_server_aus:5.6:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb6adfb8-210d-4e46-82a2-1c8705928382
Version 5.0; Version 6.0Canonical identity product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9linked exactInspect 2 returned assertions
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0ac5cd5-6e58-433c-9eb3-6dfe5656463e
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e5ed5807-55b7-47c5-97a6-03233f4fbc3a
Version 2.0Canonical identity product-5fb86209cb28a171a615b064839fb8a647f4262a91b6043cb733d29a3026f76elinked exactInspect 1 returned assertions
cpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59d47e43-886e-4114-96a2-dbe719ea3a89
Version 2.0Canonical identity product-c6ae95e309497ada4c1889e6d03b86bd52986c56a51129f0b89bc25e3be2097clinked exactInspect 1 returned assertions
cpe:2.3:a:redhat:storage:2.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
52b90a04-dd6d-4ae7-a0e5-6b381127d507
Version 2.0Canonical identity product-f361d0d92654b5e2de70df275614700a64db37e58d08b8dea7fe42bedafa987clinked exactInspect 1 returned assertions
cpe:2.3:a:redhat:storage_for_public_cloud:2.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f0257753-51c3-45f2-baa4-4c1f2deab7a6
Version 10; Version 11Canonical identity product-4f2240e45c4385f8980643ce838561b90551012dc317022ee66a7d71a9db8e28linked exactInspect 3 returned assertions
cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d1d7b467-58dd-45f1-9f1f-632620df072a
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
88d6e858-fd8f-4c55-b7d5-ceeda2bba898
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db4d6749-81a1-41d7-bf4f-1c45a7f49a22
Version 10; Version 11Canonical identity product-bd4950335ff1f3f03b9dd6fa5c596f7c67c9ea6d150272de074ec3767af3532alinked exactInspect 2 returned assertions
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp2:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5aa37837-3083-4dc7-94f4-54fd5d7cb53c
cpe:2.3:o:suse:linux_enterprise_software_development_kit:10:sp4:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
436ef2ed-fdbb-4b64-8ec4-33c3e4253f06
Assessments
CVSS by origin
AV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.