CVE-2020-7061


heap-buffer-overflow in phar_extract_file

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.



We have discovered 398,049 live websites that are affected by CVE-2020-7061.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.3 before 7.3.15
  • from 7.4 before 7.4.3
Total Vulnerable Versions507
Vulnerable Domains398,049 live websites (3.29% of PHP install base)


Common Weakness Enumeration


CWE-125 Out-of-bounds Read


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-7061 and the relative popularity of websites


Details

  • Published - Feb 17, 2020
  • Updated - Jul 23, 2021






Countries

United States91,240 websites



France203,471 websites
Belgium9,390 websites
Poland8,817 websites
Russia8,548 websites
Italy7,813 websites
China7,010 websites
Spain6,653 websites
Germany6,282 websites
Canada5,238 websites

TLDs

.com183,934 websites
.fr91,234 websites
.org18,377 websites
.net11,543 websites
.be10,560 websites
.ru7,559 websites
.pl7,007 websites
.it6,028 websites
.eu4,242 websites
.es3,747 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-7061 through included software libraries and plugins.



References


Websites affected by CVE-2020-7061

Top websites that are affected by CVE-2020-7061. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
******.com France*,***
**********.com France*,***
************.org France*,***
***.******.com France*,***
*************.com GB*,***
***.***********.com GB**,***
******.****.ru Russia**,***
*******.**.kr Korea, South**,***
*******************.com United States**,***
**************.com United States**,***
See full domain list