← back
CVE-2012-2335observed exploitation

CVE-2012-2335

37Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 33%
from disclosure to weapon
Published on NVDMay 11
VulnCheck+2075d
exploitation probability
33%top 2% of all CVEs
observed exploitation
yesVulnCheck
php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c component and a query string beginning with a +- sequence.
Affected products
n/a · n/a