Description
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
References (36)
... and 16 more
Scores
CVSS v3
9.8
EPSS
0.3887
EPSS Percentile
97.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-131
Status
published
Products (9)
apple/mac_os_x
< 10.5.4
apple/mac_os_x_server
< 10.5.4
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
7.04
canonical/ubuntu_linux
7.10
canonical/ubuntu_linux
8.04
fedoraproject/fedora
8
fedoraproject/fedora
9
php/php
< 5.2.6
Published
May 05, 2008
Tracked Since
Feb 18, 2026