EUVD-2024-44188
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 12 Jun 2024. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- 8 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2024-0414Kwetsbaarheden verholpen in Oracle Communications
- csaf_ncscnl · NCSC-2024-0243Kwetsbaarheden verholpen in PHP
- csaf_ncscnl · NCSC-2024-0411Kwetsbaarheden verholpen in Oracle Database producten
