The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.
We have discovered 178,622 live websites that are affected by CVE-2010-1128.
Product | |
Category | Programming Languages |
Vulnerable Domains | 178,622 live websites (2.05% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 78 versions ( 14.26% of all versions) |
![]() | 13,377 websites |
![]() | 96,895 websites |
![]() | 12,852 websites |
![]() | 7,400 websites |
![]() | 7,134 websites |
![]() | 5,391 websites |
![]() | 4,098 websites |
![]() | 3,621 websites |
![]() | 3,218 websites |
.com | 104,469 websites |
.de | 10,923 websites |
.info | 8,308 websites |
.net | 5,384 websites |
.ru | 3,585 websites |
.org | 3,094 websites |
.jp | 2,255 websites |
.fr | 2,191 websites |
.cz | 2,050 websites |
.it | 1,831 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.com | ![]() | *** | |
**********.us | ![]() | *,*** | |
*****.***.tw | ![]() | *,*** | |
**********.*****.de | ![]() | *,*** | |
***.**********.us | ![]() | *,*** | |
***********.jp | ![]() | **,*** | |
****.info | ![]() | **,*** | |
*****.jp | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*********.com | ![]() | **,*** |
FAQ