In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.
We have discovered 347,540 live websites that are affected by CVE-2020-7068.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 347,540 live websites (4.73% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 63 versions ( 12% of all versions) |
| 117,220 websites | |
| 126,296 websites | |
| 10,937 websites | |
| 10,439 websites | |
| 10,021 websites | |
| 6,322 websites | |
| 5,741 websites | |
| 5,712 websites | |
| 4,880 websites | |
| 4,307 websites |
| .com | 124,367 websites |
| .ru | 67,741 websites |
| .fr | 51,727 websites |
| .org | 11,510 websites |
| .net | 9,855 websites |
| .be | 6,401 websites |
| .de | 5,766 websites |
| .pl | 5,468 websites |
| .it | 4,779 websites |
| .nl | 3,178 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *.cn | *,*** | ||
| *****.pl | *,*** | ||
| ****.neustar | *,*** | ||
| *********.com | *,*** | ||
| ****.com | *,*** | ||
| *****.com | *,*** | ||
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| ***.****.gov | *,*** | ||
| *****.**.com | *,*** |
FAQ