In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.
We have discovered 128,163 live websites that are affected by CVE-2024-11235.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 128,163 live websites (1.76% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 24 versions ( 4.68% of all versions) |
| 19,846 websites | |
| 58,508 websites | |
| 4,754 websites | |
| 4,315 websites | |
| 4,301 websites | |
| 3,027 websites | |
| 2,981 websites | |
| 2,348 websites | |
| 2,300 websites | |
| 2,243 websites |
| .com | 47,646 websites |
| .fr | 24,531 websites |
| .org | 6,074 websites |
| .com.br | 4,097 websites |
| .ru | 4,068 websites |
| .net | 4,039 websites |
| .be | 3,140 websites |
| .pl | 2,915 websites |
| .it | 2,350 websites |
| .de | 2,091 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****************.com | *,*** | ||
| *******.com | *,*** | ||
| ******.com | *,*** | ||
| *******.com | *,*** | ||
| *****.com | *,*** | ||
| *******************.com | *,*** | ||
| ************.com | *,*** | ||
| ******************.com | *,*** | ||
| ************.jp | *,*** | ||
| **********.com | **,*** |
FAQ