Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-2311

EPSS 74.53% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-2311

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
PHP SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHP是一种在服务器端执行的脚本语言。 PHP存在SQL注入漏洞,该漏洞源于解析某些QUERY_STRING参数时的错误。攻击者可利用该漏洞泄露PHP源代码或者执行任意代码,操控受影响系统。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-2311

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-2311

登录查看更多情报信息。

Same Patch Batch · n/a · 2012-05-11 · 19 CVEs total

CVE-2012-0656Apple Mac OS X ‘LoginUIFramework’ 竞争条件漏洞
CVE-2012-0676Apple Safari ‘WebKit’ 输入验证漏洞
CVE-2012-0675Apple Mac OS X ‘Time Machine’ 授权问题漏洞
CVE-2012-0662Apple Mac OS X ‘Security Framework’ 整数溢出漏洞
CVE-2012-0661Apple Mac OS X ‘QuickTime’ 释放后使用漏洞
CVE-2012-0660Apple Mac OS X ‘QuickTime’ 缓冲区溢出漏洞
CVE-2012-0659Apple Mac OS X ‘QuickTime’ 整数溢出漏洞
CVE-2012-0658Apple Mac OS X ‘QuickTime’ 缓冲区溢出漏洞
CVE-2012-0657Apple Mac OS X ‘Quartz Composer’ 权限许可和访问控制漏洞
CVE-2012-1823PHP ‘php-cgi’ 参数信息泄漏漏洞
CVE-2012-0655Apple Mac OS X ‘libsecurity’ 加密问题漏洞
CVE-2012-0654Apple Mac OS X ‘libsecurity’ 缓冲区溢出漏洞
CVE-2012-0652Apple Mac OS X ‘Login Window’ 信息泄露漏洞
CVE-2012-0651Apple Mac OS X ‘Directory Service’ 信息泄露漏洞
CVE-2012-0649Apple Mac OS X ‘blued’ 竞争条件漏洞
CVE-2012-2336PHP 输入验证错误漏洞
CVE-2012-2335PHP ‘php-wrapper.fcgi’ 权限许可和访问控制问题漏洞
CVE-2012-2329PHP ‘apache_request_headers’ 函数缓冲区溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2012-2311

No comments yet


Leave a comment