PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.
We have discovered 325,640 live websites that are affected by CVE-2006-7243.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 325,640 live websites (4.43% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 36 versions ( 7.05% of all versions) |
| 26,701 websites | |
| 103,340 websites | |
| 30,984 websites | |
| 22,268 websites | |
| 22,228 websites | |
| 14,001 websites | |
| 13,060 websites | |
| 10,838 websites | |
| 9,508 websites | |
| .com | 150,125 websites |
| .ru | 26,803 websites |
| .de | 20,862 websites |
| .net | 11,413 websites |
| .info | 9,079 websites |
| .jp | 6,472 websites |
| .org | 6,222 websites |
| .nl | 6,192 websites |
| .it | 4,110 websites |
| .cz | 3,923 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| **********.com | *** | ||
| **********.us | *,*** | ||
| *****.***.tw | *,*** | ||
| *********.com | *,*** | ||
| *********.com | *,*** | ||
| ********************.ru | *,*** | ||
| **********.*****.de | *,*** | ||
| ***.**********.us | *,*** | ||
| ********.*************.si | **,*** |