PHP contains a flaw related to the PHP-CGI module. The issue is triggered when a remote attacker sends command-line arguments as part of a query string, which are passed directly to the php-cgi program. This may allow an attacker to execute arbitrary code.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public,
Exploit Commercial
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 5.3.13, 5.4.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.