In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
We have discovered 141,544 live websites that are affected by CVE-2020-7061.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 141,544 live websites (1.94% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 18 versions ( 3.49% of all versions) |
| 11,615 websites | |
| 96,277 websites | |
| 4,268 websites | |
| 4,089 websites | |
| 3,691 websites | |
| 2,560 websites | |
| 2,265 websites | |
| 2,229 websites | |
| 1,683 websites | |
| 1,628 websites |
| .com | 54,876 websites |
| .fr | 40,282 websites |
| .org | 5,224 websites |
| .be | 4,766 websites |
| .net | 3,903 websites |
| .pl | 3,637 websites |
| .ru | 3,621 websites |
| .it | 2,678 websites |
| .eu | 1,948 websites |
| .es | 1,639 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.com | *,*** | ||
| ******.com | *,*** | ||
| *********.be | **,*** | ||
| *********.fr | **,*** | ||
| ****.*********.com | **,*** | ||
| ***********.******.**.com | **,*** | ||
| ****.***********.com | **,*** | ||
| **********.*********.com | **,*** | ||
| **********.com | **,*** | ||
| ****.com | **,*** |
FAQ