Description
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Other Vulnerability (CVE-2003-0016)
Apache Traffic Server CVE-2023-33933 Vulnerability (CVE-2023-33933)
MySQL CVE-2012-0489 Vulnerability (CVE-2012-0489)
Magento Incorrect Authorization Vulnerability (CVE-2020-9692)
WordPress Plugin Product Catalog X Cross-Site Request Forgery (1.5.12)