CVE

Id
30716  
CVE No.
CVE-2008-0599  
Status
Candidate  
Description
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.  
Phase
Assigned (20080205)  
Votes
None (candidate not yet proposed)  
Comments