CVE-2007-0906

Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions. NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885). NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).


We have discovered 127,941 live websites that are affected by CVE-2007-0906.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains127,941 live websites (1.47% of PHP install base)
Vulnerable Versions
  • from 0 before 5.2.1
Vulnerable Versions Count66 versions ( 12.07% of all versions)



Details

  • Published - Feb 14, 2007
  • Updated - Aug 7, 2024

CVE-2007-0906 usage by Country

United States9,230 websites



Taiwan80,842 websites
France5,954 websites
Germany5,260 websites
Korea, South4,523 websites
Japan4,244 websites
Russia2,744 websites
Czech Republic1,028 websites
Austria974 websites

CVE-2007-0906 usage by TLD

.com83,096 websites
.info4,726 websites
.de4,154 websites
.net3,862 websites
.ru2,450 websites
.org2,103 websites
.fr1,588 websites
.jp1,411 websites
.cz892 websites
.ch791 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2007-0906

Top websites that are affected by CVE-2007-0906. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***.tw Taiwan*,***
**********.*****.de Germany*,***
***********.jp Japan**,***
****.info France**,***
******.com Taiwan**,***
*********.com United States**,***
******.com Taiwan**,***
****.com Taiwan**,***
*****.com Taiwan**,***
******.com Taiwan**,***
See full domain list

FAQ

A total of 127,941 websites have been identified as vulnerable to CVE-2007-0906, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2007-0906 vulnerability.
PHP versions before 5.2.1 are vulnerable to CVE-2007-0906.
Version 5.2.1 of PHP addresses the CVE-2007-0906 security vulnerability.

References