// For flags

CVE-2009-5016

php: XSS and SQL injection bypass via crafted overlong UTF-8 encoded string

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

Desbordamiento de enteros en xml_utf8_decode function in ext/xml/xml.c in PHP anterior v5.2.11 hace fácil para atacantes remotos superar los mecanismos de protección de secuencia de comandos en sitios cruzados (XSS) e inyección SQL a través de cadenas manipuladas que usa una codificación UTF-8 demasiado larga, una vulnerabilidad diferente que CVE-2010-3870.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-11-12 CVE Reserved
  • 2010-11-12 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 5.2.10
Search vendor "Php" for product "Php" and version " <= 5.2.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
1.0
Search vendor "Php" for product "Php" and version "1.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
2.0
Search vendor "Php" for product "Php" and version "2.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
2.0b10
Search vendor "Php" for product "Php" and version "2.0b10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0
Search vendor "Php" for product "Php" and version "3.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.1
Search vendor "Php" for product "Php" and version "3.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.2
Search vendor "Php" for product "Php" and version "3.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.3
Search vendor "Php" for product "Php" and version "3.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.4
Search vendor "Php" for product "Php" and version "3.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.5
Search vendor "Php" for product "Php" and version "3.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.6
Search vendor "Php" for product "Php" and version "3.0.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.7
Search vendor "Php" for product "Php" and version "3.0.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.8
Search vendor "Php" for product "Php" and version "3.0.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.9
Search vendor "Php" for product "Php" and version "3.0.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.10
Search vendor "Php" for product "Php" and version "3.0.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.11
Search vendor "Php" for product "Php" and version "3.0.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.12
Search vendor "Php" for product "Php" and version "3.0.12"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.13
Search vendor "Php" for product "Php" and version "3.0.13"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.14
Search vendor "Php" for product "Php" and version "3.0.14"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.15
Search vendor "Php" for product "Php" and version "3.0.15"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.16
Search vendor "Php" for product "Php" and version "3.0.16"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.17
Search vendor "Php" for product "Php" and version "3.0.17"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
3.0.18
Search vendor "Php" for product "Php" and version "3.0.18"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta_4_patch1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0
Search vendor "Php" for product "Php" and version "4.0"
beta4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.0
Search vendor "Php" for product "Php" and version "4.0.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.1
Search vendor "Php" for product "Php" and version "4.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.2
Search vendor "Php" for product "Php" and version "4.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.3
Search vendor "Php" for product "Php" and version "4.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.4
Search vendor "Php" for product "Php" and version "4.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.5
Search vendor "Php" for product "Php" and version "4.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.6
Search vendor "Php" for product "Php" and version "4.0.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.0.7
Search vendor "Php" for product "Php" and version "4.0.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.1.0
Search vendor "Php" for product "Php" and version "4.1.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.1.1
Search vendor "Php" for product "Php" and version "4.1.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.1.2
Search vendor "Php" for product "Php" and version "4.1.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2.0
Search vendor "Php" for product "Php" and version "4.2.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2.1
Search vendor "Php" for product "Php" and version "4.2.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2.2
Search vendor "Php" for product "Php" and version "4.2.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.2.3
Search vendor "Php" for product "Php" and version "4.2.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.0
Search vendor "Php" for product "Php" and version "4.3.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.1
Search vendor "Php" for product "Php" and version "4.3.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.2
Search vendor "Php" for product "Php" and version "4.3.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.3
Search vendor "Php" for product "Php" and version "4.3.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.4
Search vendor "Php" for product "Php" and version "4.3.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.5
Search vendor "Php" for product "Php" and version "4.3.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.6
Search vendor "Php" for product "Php" and version "4.3.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.7
Search vendor "Php" for product "Php" and version "4.3.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.8
Search vendor "Php" for product "Php" and version "4.3.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.9
Search vendor "Php" for product "Php" and version "4.3.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.10
Search vendor "Php" for product "Php" and version "4.3.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.3.11
Search vendor "Php" for product "Php" and version "4.3.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.0
Search vendor "Php" for product "Php" and version "4.4.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.1
Search vendor "Php" for product "Php" and version "4.4.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.2
Search vendor "Php" for product "Php" and version "4.4.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.3
Search vendor "Php" for product "Php" and version "4.4.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.4
Search vendor "Php" for product "Php" and version "4.4.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.5
Search vendor "Php" for product "Php" and version "4.4.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.6
Search vendor "Php" for product "Php" and version "4.4.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.7
Search vendor "Php" for product "Php" and version "4.4.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.8
Search vendor "Php" for product "Php" and version "4.4.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
4.4.9
Search vendor "Php" for product "Php" and version "4.4.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
beta4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.0
Search vendor "Php" for product "Php" and version "5.0.0"
rc3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.1
Search vendor "Php" for product "Php" and version "5.0.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.2
Search vendor "Php" for product "Php" and version "5.0.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.3
Search vendor "Php" for product "Php" and version "5.0.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.4
Search vendor "Php" for product "Php" and version "5.0.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.0.5
Search vendor "Php" for product "Php" and version "5.0.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.0
Search vendor "Php" for product "Php" and version "5.1.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.1
Search vendor "Php" for product "Php" and version "5.1.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.2
Search vendor "Php" for product "Php" and version "5.1.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.3
Search vendor "Php" for product "Php" and version "5.1.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.4
Search vendor "Php" for product "Php" and version "5.1.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.5
Search vendor "Php" for product "Php" and version "5.1.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.1.6
Search vendor "Php" for product "Php" and version "5.1.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.0
Search vendor "Php" for product "Php" and version "5.2.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.2.1
Search vendor "Php" for product "Php" and version "5.2.1"
-
Affected