The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.
We have discovered 309,059 live websites that are affected by CVE-2009-4418.
Product | |
Category | Programming Languages |
Vulnerable Domains | 309,059 live websites (3.54% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 84 versions ( 15.36% of all versions) |
![]() | 22,488 websites |
![]() | 98,561 websites |
![]() | 31,308 websites |
![]() | 22,890 websites |
![]() | 21,675 websites |
![]() | 13,164 websites |
![]() | 11,948 websites |
![]() | 11,747 websites |
![]() | 11,684 websites |
.com | 137,434 websites |
.ru | 26,787 websites |
.de | 20,685 websites |
.nl | 15,740 websites |
.net | 10,188 websites |
.info | 9,123 websites |
.org | 5,772 websites |
.jp | 4,043 websites |
.fr | 3,956 websites |
.dk | 3,173 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***********.com | ![]() | *** | |
**********.com | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
**********.us | ![]() | *,*** | |
*****.***.tw | ![]() | *,*** | |
********************.ru | ![]() | *,*** | |
**********.*****.de | ![]() | *,*** | |
***.**********.us | ![]() | *,*** | |
***********.jp | ![]() | **,*** | |
*******.***.ru | ![]() | **,*** |
FAQ