CVE-2008-7002

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.


We have discovered 132,393 live websites that are affected by CVE-2008-7002.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains132,393 live websites (1.52% of PHP install base)
Vulnerable Versions
  • from 0 before 5.2.5
Vulnerable Versions Count70 versions ( 12.80% of all versions)



Details

  • Published - Aug 18, 2009
  • Updated - Sep 16, 2024

CVE-2008-7002 usage by Country

United States9,635 websites



Taiwan81,392 websites
France6,188 websites
Germany5,515 websites
Japan4,841 websites
Korea, South4,588 websites
Russia2,963 websites
Italy1,304 websites
Austria1,144 websites

CVE-2008-7002 usage by TLD

.com84,636 websites
.info4,826 websites
.de4,343 websites
.net4,063 websites
.ru2,630 websites
.org2,229 websites
.fr1,634 websites
.jp1,582 websites
.co.jp941 websites
.cz933 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2008-7002

Top websites that are affected by CVE-2008-7002. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***.tw Taiwan*,***
**********.*****.de Germany*,***
***********.jp Japan**,***
****.info France**,***
******.com Taiwan**,***
*********.com United States**,***
******.com Taiwan**,***
****.com Taiwan**,***
*****.com Taiwan**,***
******.com Taiwan**,***
See full domain list

FAQ

A total of 132,393 websites have been identified as vulnerable to CVE-2008-7002, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2008-7002 vulnerability.
PHP versions before 5.2.5 are vulnerable to CVE-2008-7002.
Version 5.2.5 of PHP addresses the CVE-2008-7002 security vulnerability.