In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.
We have discovered 406,521 live websites that are affected by CVE-2020-7062.
Product | |
Category | Programming Languages |
Vulnerable Domains | 406,521 live websites (4.66% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 46 versions ( 8.41% of all versions) |
![]() | 149,681 websites |
![]() | 176,963 websites |
![]() | 11,526 websites |
![]() | 8,971 websites |
![]() | 8,618 websites |
![]() | 4,195 websites |
![]() | 3,975 websites |
![]() | 3,491 websites |
![]() | 3,276 websites |
![]() | 2,564 websites |
.com | 161,977 websites |
.fr | 69,758 websites |
.ru | 60,156 websites |
.org | 14,935 websites |
.net | 11,098 websites |
.be | 8,265 websites |
.pl | 7,269 websites |
.de | 5,466 websites |
.it | 5,232 websites |
.eu | 3,715 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*.cn | ![]() | *,*** | |
*****.***.cn | ![]() | *,*** | |
*****.cn | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
*****.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
***.***.edu | ![]() | *,*** | |
****.***.edu | ![]() | *,*** | |
***.****.gov | ![]() | *,*** |
FAQ