The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature, modification of ZVALs whose values are not updated in the associated local variables, and access of previously-freed memory.
We have discovered 154,909 live websites that are affected by CVE-2010-1915.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 154,909 live websites (2.24% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 26 versions ( 4.91% of all versions) |
| 7,676 websites | |
| 95,625 websites | |
| 10,260 websites | |
| 5,309 websites | |
| 5,088 websites | |
| 3,910 websites | |
| 3,824 websites | |
| 2,810 websites | |
| 1,954 websites |
| .com | 94,649 websites |
| .de | 9,030 websites |
| .info | 7,931 websites |
| .net | 3,962 websites |
| .ru | 2,402 websites |
| .org | 2,101 websites |
| .cz | 1,699 websites |
| .jp | 1,538 websites |
| .fr | 1,464 websites |
| .it | 1,334 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***.tw | *,*** | ||
| **********.*****.de | *,*** | ||
| ****.info | **,*** | ||
| ******.com | **,*** | ||
| *********.com | **,*** | ||
| ******.com | **,*** | ||
| ****.com | **,*** | ||
| *****.com | **,*** | ||
| ******.com | **,*** | ||
| *****.com | **,*** |