In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.
We have discovered 353,546 live websites that are affected by CVE-2023-0568.
Product | |
Category | Programming Languages |
Vulnerable Domains | 353,546 live websites (4.05% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 47 versions ( 8.59% of all versions) |
![]() | 230,213 websites |
![]() | 76,266 websites |
![]() | 8,417 websites |
![]() | 4,482 websites |
![]() | 4,367 websites |
![]() | 3,384 websites |
![]() | 2,441 websites |
![]() | 2,192 websites |
![]() | 2,148 websites |
![]() | 1,473 websites |
.com | 200,302 websites |
.fr | 30,042 websites |
.org | 25,153 websites |
.net | 10,180 websites |
.de | 6,614 websites |
.ca | 6,298 websites |
.co.uk | 5,786 websites |
.nl | 5,423 websites |
.ru | 5,016 websites |
.be | 4,459 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *** | |
******.com | ![]() | *,*** | |
****.com | ![]() | *,*** | |
***************.org | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
******.org | ![]() | *,*** | |
**********.edu | ![]() | *,*** | |
***************.com | ![]() | *,*** | |
***************.com | ![]() | *,*** | |
***********.com | ![]() | *,*** |
FAQ