CVE-2012-0830

PHP <5.3.9 - RCE

Title source: llm

Description

The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefan Esser · phpdosphp
https://www.exploit-db.com/exploits/18460

Scores

EPSS 0.2659
EPSS Percentile 96.3%

Details

CWE
CWE-399
Status published
Products (1)
php/php 5.3.9
Published Feb 06, 2012
Tracked Since Feb 18, 2026