CVE-2012-0830
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.
- Php
- = 5.3.9
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 30.1% (98th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2012-02-06
CVE-2012-0830 at NVD
2 known exploits for CVE-2012-0830
Proof-of-concept code and exploit modules indexed by Sploitus