The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.
We have discovered 88,615 live websites that are affected by CVE-2007-1380.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 88,615 live websites (1.28% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 13 versions ( 2.46% of all versions) |
| 1,387 websites | |
| 78,941 websites | |
| 1,760 websites | |
| 1,586 websites | |
| 505 websites | |
| 391 websites | |
| 347 websites | |
| 218 websites | |
| 204 websites |
| .com | 68,096 websites |
| .info | 4,256 websites |
| .de | 1,538 websites |
| .net | 848 websites |
| .jp | 601 websites |
| .ru | 358 websites |
| .org | 357 websites |
| .co.jp | 334 websites |
| .cz | 168 websites |
| .nl | 148 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***.tw | *,*** | ||
| ******.com | **,*** | ||
| ****.com | **,*** | ||
| *****.com | **,*** | ||
| ******.com | **,*** | ||
| *****.com | **,*** | ||
| *****.com | **,*** | ||
| *****.com | **,*** | ||
| ******.com | **,*** | ||
| *****.com | **,*** |
FAQ