When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.
We have discovered 131,495 live websites that are affected by CVE-2019-11035.
Product | |
Category | Programming Languages |
Vulnerable Domains | 131,495 live websites (1.51% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 49 versions ( 8.96% of all versions) |
![]() | 18,640 websites |
![]() | 68,881 websites |
![]() | 8,924 websites |
![]() | 5,669 websites |
![]() | 5,050 websites |
![]() | 3,228 websites |
![]() | 1,503 websites |
![]() | 1,301 websites |
![]() | 1,225 websites |
![]() | 1,225 websites |
.com | 54,044 websites |
.fr | 26,759 websites |
.ru | 5,169 websites |
.net | 4,225 websites |
.org | 4,199 websites |
.be | 3,343 websites |
.pl | 2,918 websites |
.it | 2,642 websites |
.de | 2,115 websites |
.eu | 1,585 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***.cn | ![]() | *,*** | |
*****.cn | ![]() | *,*** | |
******.*********.com | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*****.**.com | ![]() | *,*** | |
*****.org | ![]() | *,*** | |
********.com | ![]() | *,*** | |
***.com | ![]() | *,*** | |
********.com | ![]() | **,*** | |
*****.***.tr | ![]() | **,*** |
FAQ