CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.


We have discovered 309,059 live websites that are affected by CVE-2009-4418.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains309,059 live websites (3.54% of PHP install base)
Vulnerable Versions
  • from 0 before 5.3
Vulnerable Versions Count84 versions ( 15.36% of all versions)



Details

  • Published - Dec 24, 2009
  • Updated - Sep 17, 2024

CVE-2009-4418 usage by Country

United States22,488 websites



Taiwan98,561 websites
Russia31,308 websites
Netherlands22,890 websites
Germany21,675 websites
Japan13,164 websites
France11,948 websites
China11,747 websites
Korea, South11,684 websites

CVE-2009-4418 usage by TLD

.com137,434 websites
.ru26,787 websites
.de20,685 websites
.nl15,740 websites
.net10,188 websites
.info9,123 websites
.org5,772 websites
.jp4,043 websites
.fr3,956 websites
.dk3,173 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2009-4418

Top websites that are affected by CVE-2009-4418. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
**********.com United States***
************.***.ar Argentina*,***
**********.us United States*,***
*****.***.tw Taiwan*,***
********************.ru Russia*,***
**********.*****.de Germany*,***
***.**********.us United States*,***
***********.jp Japan**,***
*******.***.ru Russia**,***
See full domain list

FAQ

A total of 309,059 websites have been identified as vulnerable to CVE-2009-4418, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2009-4418 vulnerability.
PHP versions before 5.3 are vulnerable to CVE-2009-4418.
Version 5.3 of PHP addresses the CVE-2009-4418 security vulnerability.