Description
Acunetix has identified that Craft CMS is vulnerable to remote code execution (RCE) due to the register_argc_argv setting being enabled in the php.ini configuration. This setting allows command-line arguments to be passed to PHP scripts, potentially enabling attackers to execute arbitrary code on the server.
Remediation
Upgrade to the latest version of Craft CMS or disable register_argc_argv
References
Related Vulnerabilities
Oracle Database Server CVE-2015-0479 Vulnerability (CVE-2015-0479)
Citrix ADC/Gateway Unauthenticated Remote Code Execution
Oracle Database Server CVE-2008-1814 Vulnerability (CVE-2008-1814)
WebLogic CVE-2019-2615 Vulnerability (CVE-2019-2615)
Oracle Application Server CVE-2006-0435 Vulnerability (CVE-2006-0435)