Description
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.
Affected PHP version 5.3.9.
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
WordPress Plugin Contentboxes Cross-Site Scripting (1.1)
WordPress Plugin Fancy Cats Multiple Cross-Site Scripting Vulnerabilities (1.1)
WordPress Plugin Thank You Counter Button Cross-Site Scripting (1.8.2)
WordPress 5.0 Multiple Vulnerabilities (5.0 - 5.0)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More Local File Inclusion (2.11.1)