PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.
We have discovered 132,393 live websites that are affected by CVE-2008-7002.
Product | |
Category | Programming Languages |
Vulnerable Domains | 132,393 live websites (1.52% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 70 versions ( 12.80% of all versions) |
![]() | 9,635 websites |
![]() | 81,392 websites |
![]() | 6,188 websites |
![]() | 5,515 websites |
![]() | 4,841 websites |
![]() | 4,588 websites |
![]() | 2,963 websites |
![]() | 1,304 websites |
![]() | 1,144 websites |
.com | 84,636 websites |
.info | 4,826 websites |
.de | 4,343 websites |
.net | 4,063 websites |
.ru | 2,630 websites |
.org | 2,229 websites |
.fr | 1,634 websites |
.jp | 1,582 websites |
.co.jp | 941 websites |
.cz | 933 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***.tw | ![]() | *,*** | |
**********.*****.de | ![]() | *,*** | |
***********.jp | ![]() | **,*** | |
****.info | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
****.com | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
******.com | ![]() | **,*** |
FAQ