Description
PHP in CGI mode on Windows has an argument injection vulnerability. An unauthenticated attacker can execute arbitrary commands on the affected system by sending a specially crafted HTTP request.
Remediation
Upgrade to the latest version of PHP.
References
Related Vulnerabilities
Oracle Database Server CVE-2020-2734 Vulnerability (CVE-2020-2734)
Jenkins Insufficient Verification of Data Authenticity Vulnerability (CVE-2015-7539)
MySQL CVE-2018-3277 Vulnerability (CVE-2018-3277)
MediaWiki Improper Access Control Vulnerability (CVE-2016-6331)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-6626)