Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.
We have discovered 2,118,713 live websites that are affected by CVE-2015-8617.
Product | |
Category | Programming Languages |
Vulnerable Domains | 2,118,713 live websites (24.28% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 249 versions ( 45.52% of all versions) |
![]() | 526,723 websites |
![]() | 238,107 websites |
![]() | 159,169 websites |
![]() | 150,036 websites |
![]() | 125,637 websites |
![]() | 113,278 websites |
![]() | 85,672 websites |
![]() | 75,111 websites |
![]() | 43,982 websites |
![]() | 37,409 websites |
.com | 897,083 websites |
.ru | 204,079 websites |
.de | 92,296 websites |
.net | 78,192 websites |
.nl | 57,873 websites |
.fr | 57,620 websites |
.org | 56,843 websites |
.jp | 33,546 websites |
.pl | 31,294 websites |
.co.uk | 30,911 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.org | ![]() | *** | |
*****.***********.com | ![]() | *** | |
**********.com | ![]() | *** | |
**********.com | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
*****.ru | ![]() | *,*** | |
********.*********.com | ![]() | *,*** | |
******************.com | ![]() | *,*** | |
***.org | ![]() | *,*** | |
*********.******.net | ![]() | *,*** |
FAQ