CVE Intel / CVE-2012-1823
CVE-2012-1823
application stack · apple, debian, fedoraproject, hp, opensuse, php, redhat, suse
What it is
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
Live exploitation on the huntback network (30 days)
7
attempts captured
7
distinct source IPs
2026-09-23
last seen
huntback carries a network signature for this CVE. Exploitation attempts are detected on the decoy fleet in real time.
How huntback helps
Deploy a decoy that emulates application stack and you will see every attempt at this CVE the moment it lands, with the full payload, the attacker's infrastructure, and any stage-2 loader. Then huntback can scan the attacker back.
CVSSn/a Critical
EPSS1.00 (99% pct)
In CISA KEVyes
Publishedn/a
Network detectableyes, signatured