CVE-2006-7243

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.


We have discovered 325,640 live websites that are affected by CVE-2006-7243.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains325,640 live websites (4.43% of PHP install base)
Vulnerable Versions
  • from 0 through 5.3.4
Vulnerable Versions Count36 versions ( 7.05% of all versions)



Details

  • Published - Jan 19, 2011
  • Updated - Aug 7, 2024

Website Distribution by Country

Number of websites using CVE-2006-7243
United States26,701 websites



Taiwan103,340 websites
Russia30,984 websites
Germany22,268 websites
Japan22,228 websites
Korea, South14,001 websites
Netherlands13,060 websites
China10,838 websites
France9,508 websites

Website Distribution by TLD

Number of websites using CVE-2006-7243
.com150,125 websites
.ru26,803 websites
.de20,862 websites
.net11,413 websites
.info9,079 websites
.jp6,472 websites
.org6,222 websites
.nl6,192 websites
.it4,110 websites
.cz3,923 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2006-7243

Top websites that are affected by CVE-2006-7243. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
**********.com United States***
**********.us United States*,***
*****.***.tw Taiwan*,***
*********.com GB*,***
*********.com United States*,***
********************.ru Russia*,***
**********.*****.de Germany*,***
***.**********.us United States*,***
********.*************.si Slovenia**,***
See full domain list

FAQ

A total of 325,640 websites have been identified as vulnerable to CVE-2006-7243, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2006-7243 vulnerability.
PHP versions up to and including 5.3.4 are vulnerable to CVE-2006-7243.

References