Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a long string to the (1) php_escape_shell_cmd or (2) php_escape_shell_arg function, leading to a heap-based buffer overflow.
We have discovered 2,118,865 live websites that are affected by CVE-2016-1904.
Product | |
Category | Programming Languages |
Vulnerable Domains | 2,118,865 live websites (24.28% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 250 versions ( 45.70% of all versions) |
![]() | 526,740 websites |
![]() | 238,110 websites |
![]() | 159,172 websites |
![]() | 150,065 websites |
![]() | 125,640 websites |
![]() | 113,278 websites |
![]() | 85,677 websites |
![]() | 75,148 websites |
![]() | 43,982 websites |
![]() | 37,409 websites |
.com | 897,143 websites |
.ru | 204,080 websites |
.de | 92,296 websites |
.net | 78,198 websites |
.nl | 57,874 websites |
.fr | 57,621 websites |
.org | 56,849 websites |
.jp | 33,546 websites |
.pl | 31,295 websites |
.co.uk | 30,911 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.org | ![]() | *** | |
*****.***********.com | ![]() | *** | |
**********.com | ![]() | *** | |
**********.com | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
*****.ru | ![]() | *,*** | |
********.*********.com | ![]() | *,*** | |
******************.com | ![]() | *,*** | |
***.org | ![]() | *,*** | |
*********.******.net | ![]() | *,*** |
FAQ