CVE-2021-21706


ZipArchive::extractTo may extract outside of destination dir

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.



We have discovered 977,161 live websites that are affected by CVE-2021-21706.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.3 before 7.3.31
  • from 7.4 before 7.4.24
  • from 8 before 8.0.11
Total Vulnerable Versions507
Vulnerable Domains977,161 live websites (8.08% of PHP install base)


Common Weakness Enumeration


CWE-24 Path Traversal: '../filedir'


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2021-21706 and the relative popularity of websites


Details

  • Published - Sep 21, 2021
  • Updated - Oct 29, 2021

Credits

  • reported by vi at hackberry dot xyz





Countries

United States361,832 websites



France251,148 websites
Germany29,791 websites
Russia27,604 websites
GB22,928 websites
Canada21,924 websites
Brazil20,498 websites
Poland18,779 websites
Italy18,429 websites
Spain18,018 websites

TLDs

.com485,716 websites
.fr111,762 websites
.org56,055 websites
.net30,811 websites
.ru22,504 websites
.de18,354 websites
.com.br16,635 websites
.pl14,409 websites
.be13,985 websites
.co.uk13,710 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2021-21706 through included software libraries and plugins.



References


Websites affected by CVE-2021-21706

Top websites that are affected by CVE-2021-21706. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.pl Poland*,***
*******.com Germany*,***
****.org GB*,***
***************.org United States*,***
***.ly United States*,***
**********.org United States*,***
***.**.gov United States*,***
***.**********.org United States*,***
******.com France*,***
**********.com France*,***
See full domain list