CVE-2010-3870

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.


We have discovered 322,822 live websites that are affected by CVE-2010-3870.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains322,822 live websites (4.42% of PHP install base)
Vulnerable Versions
  • from 0 through 5.3.4
Vulnerable Versions Count36 versions ( 7.02% of all versions)



Details

  • Published - Nov 12, 2010
  • Updated - Aug 7, 2024

Website Distribution by Country

Number of websites using CVE-2010-3870
United States26,100 websites



Taiwan103,328 websites
Russia30,147 websites
Japan21,855 websites
Germany21,666 websites
Korea, South13,721 websites
Netherlands12,898 websites
China10,790 websites
France9,244 websites

Website Distribution by TLD

Number of websites using CVE-2010-3870
.com149,212 websites
.ru26,017 websites
.de20,374 websites
.net11,341 websites
.info9,070 websites
.jp6,379 websites
.nl6,154 websites
.org6,138 websites
.it4,098 websites
.cz3,878 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2010-3870

Top websites that are affected by CVE-2010-3870. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
**********.com United States***
************.ru Russia***
**********.us United States*,***
*****.***.tw Taiwan*,***
*********.com GB*,***
*********.com United States*,***
********************.ru Russia*,***
**********.*****.de Germany*,***
***.**********.us United States*,***
See full domain list

FAQ

A total of 322,822 websites have been identified as vulnerable to CVE-2010-3870, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2010-3870 vulnerability.
PHP versions up to and including 5.3.4 are vulnerable to CVE-2010-3870.

References