Description
PHP in CGI mode on Windows has an argument injection vulnerability. An unauthenticated attacker can execute arbitrary commands on the affected system by sending a specially crafted HTTP request.
Remediation
Upgrade to the latest version of PHP.
References
Related Vulnerabilities
Jetty Session Fixation Vulnerability (CVE-2018-12538)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2151)
Oracle Database Server CVE-2011-0822 Vulnerability (CVE-2011-0822)
Moodle Other Vulnerability (CVE-2006-4940)
Python Uncontrolled Resource Consumption Vulnerability (CVE-2021-3733)