CVE-2020-7062

Null Pointer Dereference in PHP Session Upload Progress

In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.


We have discovered 406,521 live websites that are affected by CVE-2020-7062.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains406,521 live websites (4.66% of PHP install base)
Vulnerable Versions
  • from 7.2 before 7.2.28
  • from 7.3 before 7.3.15
  • from 7.4 before 7.4.3
Vulnerable Versions Count46 versions ( 8.41% of all versions)


Common Weakness Enumeration

CWE-476 NULL Pointer Dereference



Details

  • Published - Feb 27, 2020
  • Updated - Sep 16, 2024

CVE-2020-7062 usage by Country

United States149,681 websites



France176,963 websites
China11,526 websites
Germany8,971 websites
Russia8,618 websites
Japan4,195 websites
Poland3,975 websites
Netherlands3,491 websites
GB3,276 websites
Italy2,564 websites

CVE-2020-7062 usage by TLD

.com161,977 websites
.fr69,758 websites
.ru60,156 websites
.org14,935 websites
.net11,098 websites
.be8,265 websites
.pl7,269 websites
.de5,466 websites
.it5,232 websites
.eu3,715 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-7062

Top websites that are affected by CVE-2020-7062. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*.cn China*,***
*****.***.cn China*,***
*****.cn China*,***
*********.com China*,***
*******.com United States*,***
*****.com United States*,***
******.com United States*,***
***.***.edu United States*,***
****.***.edu United States*,***
***.****.gov United States*,***
See full domain list

FAQ

CVE-2020-7062 is NULL Pointer Dereference in PHP
A total of 406,521 websites have been identified as vulnerable to CVE-2020-7062, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2020-7062 vulnerability.
PHP versions before 7.4.3 are vulnerable to CVE-2020-7062.
Version 7.4.3 of PHP addresses the CVE-2020-7062 security vulnerability.