CVE-2015-8617

Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.


We have discovered 2,118,713 live websites that are affected by CVE-2015-8617.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains2,118,713 live websites (24.28% of PHP install base)
Vulnerable Versions
  • from 0 before 7.0.1
Vulnerable Versions Count249 versions ( 45.52% of all versions)



Details

  • Published - Jan 19, 2016
  • Updated - Aug 6, 2024

CVE-2015-8617 usage by Country

United States526,723 websites



Russia238,107 websites
France159,169 websites
Germany150,036 websites
Japan125,637 websites
Taiwan113,278 websites
Netherlands85,672 websites
China75,111 websites
GB43,982 websites
Poland37,409 websites

CVE-2015-8617 usage by TLD

.com897,083 websites
.ru204,079 websites
.de92,296 websites
.net78,192 websites
.nl57,873 websites
.fr57,620 websites
.org56,843 websites
.jp33,546 websites
.pl31,294 websites
.co.uk30,911 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2015-8617

Top websites that are affected by CVE-2015-8617. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org China***
*****.***********.com Canada***
**********.com United States***
**********.com United States***
************.***.ar Argentina*,***
*****.ru Russia*,***
********.*********.com Singapore*,***
******************.com United States*,***
***.org United States*,***
*********.******.net United States*,***
See full domain list

FAQ

A total of 2,118,713 websites have been identified as vulnerable to CVE-2015-8617, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2015-8617 vulnerability.
PHP versions before 7.0.1 are vulnerable to CVE-2015-8617.
Version 7.0.1 of PHP addresses the CVE-2015-8617 security vulnerability.