PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.
We have discovered 393,153 live websites that are affected by CVE-2006-7243.
Product | |
Category | Programming Languages |
Vulnerable Domains | 393,153 live websites (4.50% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 88 versions ( 16.09% of all versions) |
![]() | 37,424 websites |
![]() | 104,178 websites |
![]() | 38,013 websites |
![]() | 27,414 websites |
![]() | 26,383 websites |
![]() | 23,816 websites |
![]() | 16,233 websites |
![]() | 14,796 websites |
![]() | 13,389 websites |
.com | 170,144 websites |
.ru | 32,985 websites |
.de | 23,987 websites |
.nl | 16,324 websites |
.net | 15,295 websites |
.info | 9,725 websites |
.org | 8,731 websites |
.jp | 7,585 websites |
.fr | 5,188 websites |
.cz | 4,628 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***********.com | ![]() | *** | |
**********.com | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
**********.us | ![]() | *,*** | |
*****.***.tw | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
****.**********.org | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*****.org | ![]() | *,*** | |
********************.ru | ![]() | *,*** |
FAQ