Description
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-4767 Vulnerability (CVE-2015-4767)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2018-1333)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.21)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-7317)
Ruby on Rails Improper Verification of Intent by Broadcast Receiver Vulnerability (CVE-2026-33173)