In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
We have discovered 137,319 live websites that are affected by CVE-2019-11043.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 137,319 live websites (1.77% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 68 versions ( 14% of all versions) |
| 16,946 websites | |
| 52,619 websites | |
| 9,535 websites | |
| 9,281 websites | |
| 7,516 websites | |
| 5,790 websites | |
| 4,487 websites | |
| 2,708 websites | |
| 2,028 websites | |
| 1,895 websites |
| .com | 52,999 websites |
| .fr | 21,903 websites |
| .nl | 7,014 websites |
| .ru | 6,210 websites |
| .net | 3,996 websites |
| .org | 3,995 websites |
| .de | 2,988 websites |
| .be | 2,892 websites |
| .pl | 2,636 websites |
| .it | 1,960 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *.cn | *,*** | ||
| *****.cn | *,*** | ||
| *********.com | *,*** | ||
| ****.com | *,*** | ||
| *****.**.com | *,*** | ||
| *****.org | *,*** | ||
| ********.com | *,*** | ||
| ********.com | **,*** | ||
| *****.***.tr | **,*** | ||
| ********.com | **,*** |
FAQ