CVE-2012-2336 is a denial-of-service vulnerability affecting PHP versions before 5.3.13 and 5.4.3 when configured as a CGI script (php-cgi). It stems from improper handling of query strings lacking an equals sign, allowing remote attackers to inject command-line options and cause resource exhaustion. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it is easily exploitable over the network with low attack complexity and no authentication required, leading to partial availability impact. While not listed in CISA KEV, its high EPSS score and FAUCET Risk Score of 97/100 indicate significant exploitability. Although Metasploit and Nuclei do not directly reference this CVE, related CGI argument injection exploits exist on ExploitDB, and it has garnered community discussion and media coverage, including its association with RubyMiner malware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.3.12CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:* | ||
2.0b10CPE matchmatch criteria | cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.