ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.
We have discovered 2,336,345 live websites that are affected by CVE-2018-19396.
Product | |
Category | Programming Languages |
Vulnerable Domains | 2,336,345 live websites (26.77% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 307 versions ( 56.12% of all versions) |
![]() | 577,360 websites |
![]() | 257,624 websites |
![]() | 170,183 websites |
![]() | 166,961 websites |
![]() | 134,502 websites |
![]() | 113,912 websites |
![]() | 101,018 websites |
![]() | 83,720 websites |
![]() | 57,259 websites |
![]() | 41,994 websites |
.com | 979,930 websites |
.ru | 220,567 websites |
.de | 100,118 websites |
.net | 85,056 websites |
.nl | 69,526 websites |
.org | 63,111 websites |
.fr | 61,314 websites |
.co.uk | 38,938 websites |
.jp | 35,850 websites |
.pl | 35,138 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.org | ![]() | *** | |
*****.***********.com | ![]() | *** | |
**********.com | ![]() | *** | |
**********.com | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
*****.ru | ![]() | *,*** | |
********.*********.com | ![]() | *,*** | |
******************.com | ![]() | *,*** | |
***.org | ![]() | *,*** | |
*********.******.net | ![]() | *,*** |