Description
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
Remediation
References
Related Vulnerabilities
WordPress Plugin Polldaddy Polls & Ratings Cross-Site Scripting (2.0.31)
WordPress Plugin Category Specific RSS feed Subscription Cross-Site Request Forgery (2.0)
WordPress Plugin Fancy Product Designer-WooCommerce SQL Injection (4.7.4)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5615)
WordPress Plugin Developer Tools Arbitrary File Upload (1.1.4)