ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.
We have discovered 1,692,291 live websites that are affected by CVE-2018-19396.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 1,692,291 live websites (23% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 249 versions ( 49% of all versions) |
| 345,630 websites | |
| 210,675 websites | |
| 124,282 websites | |
| 112,188 websites | |
| 109,264 websites | |
| 108,728 websites | |
| 71,547 websites | |
| 63,308 websites | |
| 45,288 websites | |
| 36,468 websites |
| .com | 704,080 websites |
| .ru | 176,686 websites |
| .de | 66,314 websites |
| .net | 57,075 websites |
| .fr | 47,787 websites |
| .org | 45,709 websites |
| .nl | 45,462 websites |
| .jp | 28,991 websites |
| .co.uk | 28,376 websites |
| .it | 26,298 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.org | *** | ||
| *****.***********.com | *** | ||
| **********.com | *** | ||
| ******************.com | *,*** | ||
| ***.org | *,*** | ||
| *********.******.net | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| ********.org | *,*** | ||
| ******.de | *,*** |