ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
We have discovered 384,585 live websites that are affected by CVE-2013-4113.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 384,585 live websites (100% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 33,864 websites | |
| 103,894 websites | |
| 36,254 websites | |
| 27,444 websites | |
| 25,078 websites | |
| 24,709 websites | |
| 16,273 websites | |
| 12,544 websites | |
| 11,662 websites | |
| .com | 165,608 websites |
| .ru | 31,553 websites |
| .de | 24,217 websites |
| .nl | 16,773 websites |
| .net | 14,295 websites |
| .info | 9,496 websites |
| .org | 8,281 websites |
| .jp | 7,497 websites |
| .cz | 5,315 websites |
| .it | 4,879 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| **********.com | *** | ||
| ************.ru | *** | ||
| ***.org | *,*** | ||
| **********.us | *,*** | ||
| *****.***.tw | *,*** | ||
| ********.org | *,*** | ||
| *********.com | *,*** | ||
| *********.com | *,*** | ||
| ********************.ru | *,*** |