Description
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.
Affected PHP version 5.3.9.
Remediation
Upgrade PHP to the latest version.
References
Related Vulnerabilities
WordPress Plugin Improved user search in backend Cross-Site Request Forgery (1.2.4)
Oracle Database Server CVE-2010-4421 Vulnerability (CVE-2010-4421)
Apache Tomcat Improperly Implemented Security Check for Standard Vulnerability (CVE-2017-15706)
Jboss EAP Incorrect Authorization Vulnerability (CVE-2014-0169)