CVE-2010-3870

Php < 5.2.14 - Improper Input Validation

Title source: rule

Description

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

Exploits (1)

exploitdb WRITEUP VERIFIED
by [email protected] · phpremotephp
https://www.exploit-db.com/exploits/34950

References (33)

... and 13 more

Scores

EPSS 0.0062
EPSS Percentile 70.1%

Details

CWE
CWE-20
Status published
Products (6)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 9.10
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 10.10
php/php < 5.2.14
Published Nov 12, 2010
Tracked Since Feb 18, 2026