Description
The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.
Remediation
References
Related Vulnerabilities
Contao Improper Encoding or Escaping of Output Vulnerability (CVE-2019-19714)
Drupal Improper Input Validation Vulnerability (CVE-2016-9452)
WordPress Plugin Highlight Cross-Site Scripting (0.9.2)
WordPress Plugin WP Content Copy Protection & No Right Click Security Bypass (3.1.4)
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.1.9)