Unrated severityNVD Advisory· Published Feb 10, 2012· Updated Apr 29, 2026
CVE-2012-0831
CVE-2012-0831
Description
PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- www.securityfocus.com/bid/51954nvdPatchThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-1358-1nvdPatchThird Party Advisory
- launchpadlibrarian.net/92454212/php5_5.3.2-1ubuntu4.13.diff.gznvdExploitThird Party Advisory
- lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2012-May/080037.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2012-May/080041.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2012-03/msg00013.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2012-03/msg00016.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2012-04/msg00001.htmlnvdMailing ListThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-1307.htmlnvdThird Party Advisory
- secunia.com/advisories/48668nvdThird Party Advisory
- secunia.com/advisories/55078nvdThird Party Advisory
- support.apple.com/kb/HT5501nvdThird Party Advisory
- svn.php.net/viewvcnvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/73125nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.