CVE-2021-21702


Null Dereference in SoapClient

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.



We have discovered 830,634 live websites that are affected by CVE-2021-21702.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.3 before 7.3.27
  • from 7.4 before 7.4.15
  • from 8 before 8.0.2
Total Vulnerable Versions507
Vulnerable Domains830,634 live websites (6.87% of PHP install base)


Common Weakness Enumeration


CWE-476 NULL Pointer Dereference



Details

  • Published - Feb 1, 2021
  • Updated - Oct 20, 2021

Credits

  • Reported by jgalindo at datto dot com





Countries

United States318,595 websites



France245,470 websites
Germany19,868 websites
Canada19,136 websites
GB18,692 websites
Russia18,623 websites
Poland16,405 websites
Spain14,311 websites
Italy14,285 websites
China13,428 websites

TLDs

.com428,585 websites
.fr109,155 websites
.org50,026 websites
.net26,427 websites
.ru15,624 websites
.be13,085 websites
.pl12,745 websites
.de11,669 websites
.co.uk11,601 websites
.ca11,188 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2021-21702

Top websites that are affected by CVE-2021-21702. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.*****.pl Poland*,***
*******.com Germany*,***
***************.org United States*,***
***.**.gov United States*,***
******.com France*,***
**********.com France*,***
********.org United States*,***
***.*********.com United States*,***
****.**********.***.uk GB*,***
****.******.jp Japan*,***
See full domain list