Description
PHP in CGI mode on Windows has an argument injection vulnerability. An unauthenticated attacker can execute arbitrary commands on the affected system by sending a specially crafted HTTP request.
Remediation
Upgrade to the latest version of PHP.