The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.
We have discovered 59,809 live websites that are affected by CVE-2008-7068.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 59,809 live websites (0.77% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1 versions ( 0.20% of all versions) |
| 5,569 websites | |
| 16,585 websites | |
| 8,689 websites | |
| 5,633 websites | |
| 3,483 websites | |
| 3,276 websites | |
| 2,260 websites | |
| 1,983 websites | |
| 1,410 websites |
| .com | 24,177 websites |
| .de | 7,833 websites |
| .info | 3,471 websites |
| .net | 2,698 websites |
| .ru | 1,942 websites |
| .org | 1,493 websites |
| .cz | 1,078 websites |
| .fr | 949 websites |
| .it | 838 websites |
| .at | 734 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.*****.de | *,*** | ||
| ***********.jp | **,*** | ||
| ****.info | **,*** | ||
| ******.com | **,*** | ||
| *********.com | **,*** | ||
| *****.*****.**.kr | **,*** | ||
| **********.com | **,*** | ||
| ******.com | **,*** | ||
| **.*****.**********.com | **,*** | ||
| *****.*******.**.kr | **,*** |