In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
We have discovered 390,801 live websites that are affected by CVE-2019-11045.
Product | |
Category | Programming Languages |
Vulnerable Domains | 390,801 live websites (4.48% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 40 versions ( 7.31% of all versions) |
![]() | 143,557 websites |
![]() | 176,164 websites |
![]() | 11,020 websites |
![]() | 8,316 websites |
![]() | 7,655 websites |
![]() | 3,613 websites |
![]() | 3,159 websites |
![]() | 3,083 websites |
![]() | 2,941 websites |
![]() | 2,356 websites |
.com | 155,444 websites |
.fr | 69,498 websites |
.ru | 59,318 websites |
.org | 14,236 websites |
.net | 10,462 websites |
.be | 8,180 websites |
.pl | 6,563 websites |
.de | 5,184 websites |
.it | 5,022 websites |
.eu | 3,581 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*.cn | ![]() | *,*** | |
*****.***.cn | ![]() | *,*** | |
*****.cn | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
*****.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
***.***.edu | ![]() | *,*** | |
****.***.edu | ![]() | *,*** | |
***.****.gov | ![]() | *,*** |
FAQ