ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via a long string that is mishandled in a curl_escape call.
We have discovered 2,122,717 live websites that are affected by CVE-2016-7134.
Product | |
Category | Programming Languages |
Vulnerable Domains | 2,122,717 live websites (24.32% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 258 versions ( 47.17% of all versions) |
![]() | 527,388 websites |
![]() | 238,261 websites |
![]() | 159,390 websites |
![]() | 150,273 websites |
![]() | 125,782 websites |
![]() | 113,294 websites |
![]() | 85,765 websites |
![]() | 75,987 websites |
![]() | 44,045 websites |
![]() | 37,443 websites |
.com | 898,813 websites |
.ru | 204,147 websites |
.de | 92,434 websites |
.net | 78,367 websites |
.nl | 57,904 websites |
.fr | 57,665 websites |
.org | 57,018 websites |
.jp | 33,584 websites |
.pl | 31,312 websites |
.co.uk | 30,968 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.org | ![]() | *** | |
*****.***********.com | ![]() | *** | |
**********.com | ![]() | *** | |
**********.com | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
*****.ru | ![]() | *,*** | |
********.*********.com | ![]() | *,*** | |
******************.com | ![]() | *,*** | |
***.org | ![]() | *,*** | |
*********.******.net | ![]() | *,*** |
FAQ