Source Code Disclosure - CVE-2012-1823
- Risk:
High
- Type:
- Active
- CWE:
- CWE-20
- Summary
Some PHP versions, when configured to run using CGI, do not correctly handle query strings that lack an unescaped “=” character, enabling PHP source code disclosure, and arbitrary code execution. In this case, the contents of the PHP file were served directly to the web browser. This output will typically contain PHP, although it may also contain straight HTML.
- Solution
Upgrade to the latest stable version of PHP, or use the Apache web server and the mod_rewrite module to filter out malicious requests using the "RewriteCond" and "RewriteRule" directives.
- Other info
- <?php $x=0; echo '<h1>Welcome!</h1>'; ?>
- References
https://owasp.org/www-community/vulnerabilities/Improper_Data_Validation
https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html
Clothing giant MANGO discloses data breach exposing customer info
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped
Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control
Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access
New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
Final Windows 10 Patch Tuesday update rolls out as support ends
New Android Pixnapping attack steals MFA codes pixel-by-pixel
Microsoft: Exchange 2016 and 2019 have reached end of support
CVE-2016-7836 SKYSEA Client View Improper Authentication Vulnerability
CVE-2025-6264 Rapid7 Velociraptor Incorrect Default Permissions Vulnerability
CVE-2025-59230 Microsoft Windows Improper Access Control Vulnerability
CVE-2025-24990 Microsoft Windows Untrusted Pointer Dereference Vulnerability
CVE-2025-47827 IGEL OS Use of a Key Past its Expiration Date Vulnerability
CVE-2025-27915 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
CVE-2025-61882 Oracle E-Business Suite Unspecified Vulnerability
CVE-2010-3765 Mozilla Multiple Products Remote Code Execution Vulnerability
CVE-2011-3402 Microsoft Windows Remote Code Execution Vulnerability
InformationalUser Controllable JavaScript Event (XSS)
InformationalModern Web Application
InformationalCORS Header
HighPath Traversal
LowInformation Disclosure - Sensitive Information in Browser sessionStorage
Free online web security scanner