CVE-2012-2311 is a critical remote code execution vulnerability affecting PHP versions before 5.3.13 and 5.4.3 when configured as a CGI script (php-cgi). It stems from an incomplete fix for CVE-2012-1823, allowing attackers to inject command-line options via specially crafted query strings containing "%3D" without an equals sign. This vulnerability carries a high CVSS score of 7.5, indicating a network-based attack with low complexity, requiring no authentication, and potentially leading to full compromise of confidentiality, integrity, and availability. Exploit code is publicly available on ExploitDB, including Metasploit modules, and it has seen significant community discussion and media coverage, with reports of active exploitation by malware like RubyMiner.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.3.12CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:* | ||
2.0b10CPE matchmatch criteria | cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.