exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.
We have discovered 2,535,074 live websites that are affected by CVE-2018-12882.
Product | |
Category | Programming Languages |
Vulnerable Domains | 2,535,074 live websites (29.05% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 327 versions ( 59.78% of all versions) |
![]() | 617,840 websites |
![]() | 284,503 websites |
![]() | 199,689 websites |
![]() | 181,416 websites |
![]() | 149,324 websites |
![]() | 115,387 websites |
![]() | 114,363 websites |
![]() | 89,613 websites |
![]() | 61,443 websites |
![]() | 45,272 websites |
.com | 1,053,405 websites |
.ru | 242,984 websites |
.de | 107,297 websites |
.net | 90,793 websites |
.nl | 81,050 websites |
.fr | 72,229 websites |
.org | 68,741 websites |
.co.uk | 42,437 websites |
.jp | 39,530 websites |
.pl | 38,273 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.org | ![]() | *** | |
*****.***********.com | ![]() | *** | |
**********.com | ![]() | *** | |
**********.com | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
*****.ru | ![]() | *,*** | |
********.*********.com | ![]() | *,*** | |
******************.com | ![]() | *,*** | |
***.org | ![]() | *,*** | |
*********.******.net | ![]() | *,*** |