CVE-2012-1823 is an argument-injection vulnerability in PHP CGI request handling. PHP versions before 5.3.12 and PHP 5.4.x before 5.4.2 do not correctly reject query strings lacking a literal equals sign before processing them as CGI arguments. A remote attacker can supply PHP command-line options through the query string, altering interpreter configuration and causing attacker-controlled PHP supplied in the request body to be executed. The issue affects deployments configured to invoke PHP through CGI.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (9 hidden).
This 13-file repository is a self-contained Docker/CTF laboratory for PHP-CGI argument injection. Its main operational entry point, exploit.sh, uses curl to POST a PHP payload to /index.php while injecting php-cgi -d options through a query string. The injected options set allow_url_include=1 and auto_prepend_file=php://input, causing PHP to execute the request body before the normal application page. The payload reports context and executes a supplied shell command; its default reads the container flag. Dockerfile builds intentionally unpatched PHP 5.4.1 with CGI support on Debian Bullseye, installs it as /usr/lib/cgi-bin/php-cgi, and configures Apache mod_actions to route .php files to that binary. config/apache-vhost.conf is central to the vulnerability: CGI query-string words become argv, and old php-cgi parses those attacker-controlled words as command-line options. config/php.ini disables cgi.force_redirect and leaves allow_url_include disabled by default so the exploit must enable it at runtime. Dockerfile.vulhub provides a fallback image, docker-compose.yml publishes container port 80 as localhost:8080, start.sh launches Apache, app/index.php is a benign status page, and poc.http provides raw Linux and Windows-form requests. The repository accurately distinguishes its runnable Linux target from real CVE-2024-4577. The Linux container uses literal '-' option injection against pre-2012-patch PHP 5.4.1, therefore demonstrating CVE-2012-1823's underlying CGI argument-injection/RCE primitive. poc.http also documents the %AD soft-hyphen form used by CVE-2024-4577 on affected Windows PHP-CGI systems, where Windows best-fit decoding converts %AD to '-' after the original hardening check.
This repository is a small standalone exploit for CVE-2012-1823, the PHP-CGI argument injection vulnerability that enables unauthenticated remote code execution. The repository contains two files: a README with background, affected versions, impact, and mitigation guidance; and a single Python exploit script, exploit.py, which is the operational entry point. The exploit script defines a PHPCGIExploit class that builds a malicious target URL by appending a crafted query string to the supplied base URL: /?-d+allow_url_include%3d1+-d+auto_prepend_file%3dphp://input. This abuses PHP-CGI argument parsing to enable allow_url_include and set auto_prepend_file to php://input, causing PHP code in the POST body to be executed. The execute() method sends a POST request containing a PHP payload of the form <?php system('{command}'); die(); ?>, which runs an arbitrary OS command on the target and returns the output. The script supports both one-shot command execution via -c/--command and an interactive shell loop via interactive_shell(). Operationally, the exploit includes basic usability features rather than advanced tradecraft: configurable timeout, retry handling for transient HTTP errors, optional HTTP/HTTPS proxy support, verbose logging, and colored console output via rich. There is no target discovery, vulnerability verification, authentication handling, persistence mechanism, or post-exploitation automation. Because it delivers a hardcoded but functional command-execution payload, it is best classified as OPERATIONAL rather than a simple POC. Fingerprintable observables are limited and directly tied to exploitation: the crafted CGI argument injection path/query, use of php://input as the prepend source, and standard HTTP/HTTPS transport. No hardcoded victim IPs, domains, C2 infrastructure, registry keys, or filesystem paths are embedded beyond example CLI values. Overall, the repository's purpose is straightforward: provide a direct Python-based RCE exploit against vulnerable PHP CGI deployments affected by CVE-2012-1823.
This repository is a small standalone Python proof-of-concept exploit for CVE-2012-1823, a PHP-CGI argument injection vulnerability that can lead to remote code execution. The repository contains only two files: a README with usage instructions and vulnerability context, and a single executable script, exploit.py. The Python script uses argparse for CLI input and requests for HTTP communication. Its core logic builds a malicious URL by appending a crafted query string to /index.php that injects php-cgi directives: allow_url_include=1 and auto_prepend_file=php://input. It then sends a POST request whose body contains PHP code invoking system() with an attacker-controlled command. If successful, the target executes the command and returns the output in the HTTP response. The exploit is operational but basic: it supports arbitrary command execution, has a hardcoded target path (/index.php), and does not include advanced features such as vulnerability checking, shell staging, authentication handling, or payload obfuscation beyond simple inline PHP. No external C2, callback infrastructure, or hardcoded remote IP/domain endpoints are present; the only network target is the user-supplied URL.
This repository contains two Python scripts and a README file. The main exploit script, 'CVE-2012-1823.py', targets the PHP CGI Argument Injection vulnerability (CVE-2012-1823). It allows the user to specify a target URL, HTTP Basic Auth credentials, and an arbitrary command to execute on the target server. The script constructs a request to the '/cgi-bin/test-cgi' endpoint, appending the user-supplied command as a query parameter, and attempts to execute it via the vulnerable CGI interface. The script prints the HTTP response and indicates whether the exploit was likely successful. The second script, 'CVE-2012-1823,CVE-2021-2291.py', is a detection tool that checks if a target is vulnerable to CVE-2012-1823 (by testing for partial content responses to a Range header) and CVE-2021-2291 (by checking for the 'X-Powered-By' header in the HTTP response). Both scripts require the user to provide a URL and HTTP Basic Auth credentials. The README provides brief usage instructions and notes that the scripts were tested on Kali Linux. No hardcoded IP addresses or domains are present; the scripts require user-supplied targets. The main attack vector is network-based, exploiting web server endpoints via HTTP requests.
This repository contains a single Metasploit module: 'php_cgi_arg_injection.rb', which exploits the PHP CGI Argument Injection vulnerability (CVE-2012-1823). The exploit targets PHP when run as a CGI (not as an Apache module), specifically versions up to 5.3.12 and 5.4.2. By abusing the way PHP CGI parses command-line arguments, the module injects PHP configuration directives via the '-d' flag, allowing the attacker to enable dangerous options and execute arbitrary PHP code. The exploit is delivered over HTTP, requiring the attacker to specify a URI that points to a CGI-handled PHP script on the target server. The module also includes special handling for Plesk environments, using a default URI of '/phppath/php'. The payload is arbitrary PHP code, provided by the Metasploit framework, and is sent in the HTTP POST body. The module is operational and can be used to achieve remote code execution on vulnerable servers. The repository is structured as a single Ruby file, following the standard Metasploit module format, and is intended for use within the Metasploit framework.
This repository contains a Bash script (php_cgi.sh) that exploits the PHP CGI Argument Injection vulnerability (CVE-2012-1823). The exploit targets PHP versions before 5.3.12 and 5.4.2 when configured as a CGI script (php-cgi) and accessible over HTTP. The script takes a target URL and a command as arguments, then sends a specially crafted HTTP POST request to the target, injecting a PHP payload via the 'auto_prepend_file' directive using 'php://input'. This payload executes the supplied system command on the target server. The repository also includes a README.md with usage instructions and a description of the vulnerability. The main entry point is the php_cgi.sh script, and the exploit is operational, providing remote command execution on vulnerable servers.
This repository provides a proof-of-concept (POC) environment for exploiting the PHP-CGI remote code execution vulnerability (CVE-2012-1823). The structure includes a Dockerfile and docker-compose.yml to set up a vulnerable PHP 5.4.1-CGI environment, with web content in the 'www' directory. The main exploit capability is remote code execution via specially crafted HTTP requests that abuse the way PHP-CGI parses query strings as command-line arguments. The README.md provides detailed background, exploitation steps, and example payloads. The main vulnerable endpoint is 'http://your-ip:8080/index.php', which can be exploited by appending malicious query strings and POST data. The repository is intended for educational or testing purposes, demonstrating how attackers can achieve arbitrary code execution on misconfigured or unpatched PHP-CGI servers.
This repository is a comprehensive exploit toolkit targeting multiple well-known vulnerabilities and misconfigurations in Linux-based services, primarily for educational or penetration testing purposes. It contains step-by-step walkthroughs, Metasploit module usage, and some custom scripts (notably a PHP backdoor) for exploiting services such as vsftpd 2.3.4 (CVE-2011-2523), Samba (CVE-2007-2447), distccd (CVE-2004-2687), PHP-CGI (CVE-2012-1823), UnrealIRCd (CVE-2010-2075), as well as misconfigurations in NFS, PostgreSQL, MySQL, and privilege escalation via udev. The structure is organized by target service, with each directory containing detailed attack instructions, relevant commands, and in some cases, exploit code or payloads. The main capabilities include remote code execution, reverse shell access, privilege escalation, database extraction, and persistent access via SSH key injection. The repository is operational in maturity, providing working attack chains and payloads, and is suitable for use in penetration testing labs such as Metasploitable. No fake or detection-only scripts were identified; all content is focused on exploitation.
This repository contains a Python script (cve-2012-1823_VulCheck.py) designed to check for and exploit the CVE-2012-1823 vulnerability in PHP-CGI. The script takes a target domain or IP as input, constructs HTTP requests to common PHP-CGI endpoints (/cgi-bin/php, /cgi-bin/php5, /cgi-bin/php-cgi, /cgi-bin/php.cgi), and attempts to exploit the vulnerability by sending a specially crafted payload. The payload is a PHP code snippet that, if executed, confirms remote code execution by returning a specific string. The script prints the server's response and notifies the user if the target is vulnerable. The repository also includes a minimal readme.md file. The exploit is operational and provides a clear indication of vulnerability, but does not provide a full-featured shell or post-exploitation capabilities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in PHP-CGI, exploited by Morte Loader operators for initial compromise of edge devices and web applications.
A remote code execution vulnerability in PHP-CGI, exploited by Morte Loader operators to gain initial access to devices.
A remote code execution vulnerability in PHP CGI that is being exploited in automated cryptomining campaigns.
A PHP CGI vulnerability that remains actively targeted years later as part of automated exploitation chains used to deploy cryptominers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.