Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions. NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885). NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).
We have discovered 127,941 live websites that are affected by CVE-2007-0906.
Product | |
Category | Programming Languages |
Vulnerable Domains | 127,941 live websites (1.47% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 66 versions ( 12.07% of all versions) |
![]() | 9,230 websites |
![]() | 80,842 websites |
![]() | 5,954 websites |
![]() | 5,260 websites |
![]() | 4,523 websites |
![]() | 4,244 websites |
![]() | 2,744 websites |
![]() | 1,028 websites |
![]() | 974 websites |
.com | 83,096 websites |
.info | 4,726 websites |
.de | 4,154 websites |
.net | 3,862 websites |
.ru | 2,450 websites |
.org | 2,103 websites |
.fr | 1,588 websites |
.jp | 1,411 websites |
.cz | 892 websites |
.ch | 791 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***.tw | ![]() | *,*** | |
**********.*****.de | ![]() | *,*** | |
***********.jp | ![]() | **,*** | |
****.info | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
****.com | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
******.com | ![]() | **,*** |
FAQ