In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to use the proxy to perform arbitrary HTTP requests originating from the server, thus potentially gaining access to resources not normally available to the external user.
We have discovered 757,683 live websites that are affected by CVE-2024-11234.
Product | |
Category | Programming Languages |
Vulnerable Domains | 757,683 live websites (8.68% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 71 versions ( 12.98% of all versions) |
![]() | 178,746 websites |
![]() | 91,227 websites |
![]() | 85,693 websites |
![]() | 74,042 websites |
![]() | 53,196 websites |
![]() | 51,528 websites |
![]() | 48,994 websites |
![]() | 20,395 websites |
![]() | 14,257 websites |
![]() | 11,284 websites |
.com | 263,806 websites |
.ru | 47,947 websites |
.nl | 44,983 websites |
.se | 36,058 websites |
.fr | 33,719 websites |
.org | 27,691 websites |
.com.br | 21,432 websites |
.de | 19,744 websites |
.net | 19,593 websites |
.co.uk | 15,779 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *** | |
******.com | ![]() | *,*** | |
*****.cz | ![]() | *,*** | |
********.********.it | ![]() | *,*** | |
***********.de | ![]() | *,*** | |
***.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
******.com | ![]() | *,*** | |
****.com | ![]() | *,*** |
FAQ