In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
We have discovered 319,905 live websites that are affected by CVE-2024-8932.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 319,905 live websites (4.19% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 71 versions ( 14% of all versions) |
| 72,951 websites | |
| 81,872 websites | |
| 18,229 websites | |
| 17,658 websites | |
| 13,144 websites | |
| 12,568 websites | |
| 10,676 websites | |
| 8,824 websites | |
| 7,237 websites | |
| 6,423 websites |
| .com | 115,183 websites |
| .fr | 33,543 websites |
| .ru | 15,152 websites |
| .org | 14,590 websites |
| .se | 12,638 websites |
| .nl | 11,436 websites |
| .com.br | 9,381 websites |
| .net | 9,320 websites |
| .com.au | 6,143 websites |
| .de | 6,088 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****************.com | *,*** | ||
| ********.********.it | *,*** | ||
| ****.*****.com | *,*** | ||
| *******.com | *,*** | ||
| ******.com | *,*** | ||
| ******.com | *,*** | ||
| ***.com | *,*** | ||
| *****.com | *,*** | ||
| ***********************.com | *,*** | ||
| **********.edu | *,*** |
FAQ