In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
We have discovered 415,221 live websites that are affected by CVE-2024-5458.
Product | |
Category | Programming Languages |
Vulnerable Domains | 415,221 live websites (4.76% of PHP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 57 versions ( 10.42% of all versions) |
![]() | 99,898 websites |
![]() | 77,653 websites |
![]() | 64,986 websites |
![]() | 43,029 websites |
![]() | 27,398 websites |
![]() | 14,184 websites |
![]() | 8,643 websites |
![]() | 7,553 websites |
![]() | 6,975 websites |
![]() | 4,847 websites |
.com | 162,408 websites |
.fr | 30,300 websites |
.nl | 25,434 websites |
.org | 16,783 websites |
.com.br | 14,631 websites |
.ru | 14,569 websites |
.net | 11,163 websites |
.de | 7,121 websites |
.be | 6,887 websites |
.cn | 6,844 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *** | |
******.com | ![]() | *,*** | |
*****.cz | ![]() | *,*** | |
********.********.it | ![]() | *,*** | |
***.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
****.com | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
*****.com | ![]() | *,*** | |
**********.edu | ![]() | *,*** |
FAQ