In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
We have discovered 127,062 live websites that are affected by CVE-2022-31631.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 127,062 live websites (1.74% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 43 versions ( 8.33% of all versions) |
| 29,070 websites | |
| 61,426 websites | |
| 4,470 websites | |
| 3,443 websites | |
| 3,398 websites | |
| 2,643 websites | |
| 2,512 websites | |
| 2,271 websites | |
| 1,970 websites | |
| 1,424 websites |
| .com | 46,862 websites |
| .fr | 25,778 websites |
| .org | 5,809 websites |
| .ru | 4,459 websites |
| .net | 3,812 websites |
| .pl | 3,253 websites |
| .it | 3,194 websites |
| .be | 3,107 websites |
| .de | 2,568 websites |
| .nl | 2,452 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.edu | *,*** | ||
| ***************.com | *,*** | ||
| ***********.com | *,*** | ||
| ******************.com | **,*** | ||
| ****.org | **,*** | ||
| **********.com | **,*** | ||
| ***.org | **,*** | ||
| *****.sh | **,*** | ||
| ***.cc | **,*** | ||
| *****.de | **,*** |
FAQ