Description
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.
Affected PHP version 5.3.9.
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.78)
WordPress Plugin Ultimate WordPress Auction Multiple Vulnerabilities (4.0.5)
WordPress Plugin Ultimate GDPR & CCPA Compliance Toolkit for WordPress Security Bypass (2.4)
WordPress Plugin WP HTML Sitemap Cross-Site Request Forgery (1.2)