CVE-2012-0830 is a remote code execution vulnerability in PHP 5.3.9, specifically within the php_register_variable_ex function. This flaw, an incorrect fix for a previous vulnerability, allows attackers to execute arbitrary code by sending requests with a large number of array variables. With a CVSS score of 7.5, it is a high-severity vulnerability that can be exploited remotely with low complexity, potentially leading to partial compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit/Nuclei modules, a Denial of Service exploit for a related PHP version exists on ExploitDB, and the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.3.9CPE matchmatch criteria | cpe:2.3:a:php:php:5.3.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.