When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
We have discovered 95,587 live websites that are affected by CVE-2019-11034.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 95,587 live websites (1.29% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 49 versions ( 9.66% of all versions) |
| 9,160 websites | |
| 49,065 websites | |
| 6,422 websites | |
| 4,570 websites | |
| 4,068 websites | |
| 2,511 websites | |
| 2,253 websites | |
| 1,595 websites | |
| 1,311 websites | |
| 1,149 websites |
| .com | 37,806 websites |
| .fr | 20,491 websites |
| .ru | 3,842 websites |
| .org | 2,885 websites |
| .net | 2,760 websites |
| .be | 2,581 websites |
| .pl | 2,269 websites |
| .de | 1,677 websites |
| .it | 1,574 websites |
| .eu | 1,232 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| ****.com | *,*** | ||
| *****.**.com | *,*** | ||
| *****.org | *,*** | ||
| ********.com | *,*** | ||
| ********.com | **,*** | ||
| *****.***.tr | **,*** | ||
| ********.com | **,*** | ||
| ****.ru | **,*** | ||
| *********.fr | **,*** |
FAQ