Source Code Exposure (CVE-2012-1823)

Published on 13 May 2024
Vulnerability

Description

A vulnerability in PHP, when configured to run using CGI, allows an attacker to disclose the source code of PHP files and potentially execute arbitrary code. This occurs when a query string lacks an unescaped ‘=’ character, causing PHP to output the file contents directly.

Recommendation

Upgrade to the latest stable version of PHP or use Apache’s mod_rewrite module with RewriteCond and RewriteRule directives to filter out malicious requests.

Anandhu Krishnan
Written by
Lead Engineer

Anandhu is an accomplished Senior Lead Engineer with a strong focus on back-end development. His expertise lies in architecting and optimizing the core of software applications to ensure they run smoothly and efficiently. With a meticulous attention to detail and a deep understanding of data management and server-side operations, Anandhu has been a driving force behind the success of various back-end projects.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo