CVE-2006-7243

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.


We have discovered 393,153 live websites that are affected by CVE-2006-7243.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains393,153 live websites (4.50% of PHP install base)
Vulnerable Versions
  • from 0 before 5.3.4
Vulnerable Versions Count88 versions ( 16.09% of all versions)



Details

  • Published - Jan 19, 2011
  • Updated - Aug 7, 2024

CVE-2006-7243 usage by Country

United States37,424 websites



Taiwan104,178 websites
Russia38,013 websites
Germany27,414 websites
Japan26,383 websites
Netherlands23,816 websites
France16,233 websites
Korea, South14,796 websites
China13,389 websites

CVE-2006-7243 usage by TLD

.com170,144 websites
.ru32,985 websites
.de23,987 websites
.nl16,324 websites
.net15,295 websites
.info9,725 websites
.org8,731 websites
.jp7,585 websites
.fr5,188 websites
.cz4,628 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2006-7243

Top websites that are affected by CVE-2006-7243. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
**********.com United States***
************.***.ar Argentina*,***
**********.us United States*,***
*****.***.tw Taiwan*,***
*********.com GB*,***
****.**********.org United States*,***
*********.com United States*,***
*****.org United States*,***
********************.ru Russia*,***
See full domain list

FAQ

A total of 393,153 websites have been identified as vulnerable to CVE-2006-7243, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2006-7243 vulnerability.
PHP versions before 5.3.4 are vulnerable to CVE-2006-7243.
Version 5.3.4 of PHP addresses the CVE-2006-7243 security vulnerability.

References