Record summary

CVE-2010-3870 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPHP 5.3.2 - 'xml_utf8_decode()' UTF-8 Input ValidationExploitDB exploitby root@80sec.comNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 38