CVE-2020-7060


global buffer-overflow in mbfl_filt_conv_big5_wchar

When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the allocated buffer. This may lead to information disclosure or crash.



We have discovered 585,899 live websites that are affected by CVE-2020-7060.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.2 before 7.2.27
  • from 7.3 before 7.3.14
  • from 7.4 before 7.4.2
Total Vulnerable Versions507
Vulnerable Domains585,899 live websites (4.84% of PHP install base)


Common Weakness Enumeration


CWE-125 Out-of-bounds Read


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-7060 and the relative popularity of websites


Details

  • Published - Jan 21, 2020
  • Updated - Jul 23, 2021

Credits

  • Reported by reza at iseclab dot org





Countries

United States112,886 websites



France242,525 websites
Russia65,060 websites
China19,522 websites
Poland12,529 websites
Germany12,128 websites
Belgium11,454 websites
Italy11,403 websites
Spain9,050 websites
GB8,829 websites

TLDs

.com238,585 websites
.fr108,619 websites
.ru63,055 websites
.org23,181 websites
.net15,307 websites
.be12,852 websites
.pl9,863 websites
.it8,585 websites
.de7,349 websites
.nl6,413 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-7060 through included software libraries and plugins.



References


Websites affected by CVE-2020-7060

Top websites that are affected by CVE-2020-7060. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*.cn China*,***
***.*.cn China*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
***.*********.com China*,***
*.***.cn China*,***
***.*.***.cn China*,***
See full domain list