The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398.
We have discovered 446,732 live websites that are affected by CVE-2012-4388.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 446,732 live websites (6.45% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 63 versions ( 12% of all versions) |
| 39,286 websites | |
| 103,032 websites | |
| 49,266 websites | |
| 36,350 websites | |
| 33,155 websites | |
| 32,976 websites | |
| 14,727 websites | |
| 13,677 websites | |
| 9,083 websites |
| .com | 193,630 websites |
| .ru | 42,429 websites |
| .de | 24,913 websites |
| .net | 16,653 websites |
| .fr | 11,732 websites |
| .info | 10,263 websites |
| .org | 10,134 websites |
| .jp | 9,799 websites |
| .nl | 6,406 websites |
| .it | 5,361 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| ***.org | *,*** | ||
| ***.ru | *,*** | ||
| *****.***.tw | *,*** | ||
| *********.com | *,*** | ||
| *********.com | *,*** | ||
| ********************.ru | *,*** | ||
| *********.com | *,*** | ||
| **********.*****.de | *,*** | ||
| ******.com | *,*** |