Looking for the vulnerability index of Invicti's legacy products?
PHP Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2012-1823 - Vulnerability Database

PHP Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2012-1823

Critical
Reference: CVE-2012-1823
Title: PHP Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability
Overview:

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2 when configured as a CGI script (aka php-cgi) does not properly handle query strings that lack an (equals sign) character which allows remote attackers to execute arbitrary code by placing command-line options in the query string related to lack of skipping a certain php_getopt for the 39d39 case.