bugs.php.net
http://bugs.php.net/bug.php?id=48230 CVE-2010-3870
PHP 5.3.2 - 'xml_utf8_decode()' UTF-8 Input Validation
Record summary
CVE-2010-3870 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP 5.3.2 - 'xml_utf8_decode()' UTF-8 Input ValidationExploitDB exploitby root@80sec.comNot analyzed1 file
References
Showing 12 of 38bugs.php.netConfirmation
http://bugs.php.net/bug.php?id=49687 APPLE-SA-2011-03-21-1Vendor advisory
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html FEDORA-2010-19011Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052836.html FEDORA-2010-18976Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052845.html SUSE-SR:2010:023Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html HPSBOV02763Vendor advisory
http://marc.info/?l=bugtraq&m=133469208622507&w=2 42410Third-party advisory
http://secunia.com/advisories/42410 42812Third-party advisory
http://secunia.com/advisories/42812 sirdarckcat.blogspot.com
http://sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.html support.apple.comConfirmation
http://support.apple.com/kb/HT4581 svn.php.netConfirmation
http://svn.php.net/viewvc?view=revision&revision=304959