In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
We have discovered 350,085 live websites that are affected by CVE-2024-3096.
Product | |
Category | Programming Languages |
Vulnerable Domains | 350,085 live websites (4.01% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 51 versions ( 9.32% of all versions) |
![]() | 86,897 websites |
![]() | 76,236 websites |
![]() | 53,333 websites |
![]() | 36,597 websites |
![]() | 13,042 websites |
![]() | 9,560 websites |
![]() | 8,465 websites |
![]() | 6,709 websites |
![]() | 6,449 websites |
![]() | 3,994 websites |
.com | 139,599 websites |
.fr | 29,789 websites |
.org | 14,735 websites |
.ru | 12,613 websites |
.com.br | 12,558 websites |
.nl | 10,938 websites |
.net | 9,662 websites |
.cn | 6,653 websites |
.de | 5,924 websites |
.co.uk | 5,865 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *** | |
******.com | ![]() | *,*** | |
*****.cz | ![]() | *,*** | |
********.********.it | ![]() | *,*** | |
***.com | ![]() | *,*** | |
****.com | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*****.com | ![]() | *,*** | |
**********.edu | ![]() | *,*** | |
***************.org | ![]() | *,*** |
FAQ