CVE-2010-3870
Php < 5.2.14 - Improper Input Validation
Title source: ruleDescription
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
https://www.exploit-db.com/exploits/34950
References (33)
... and 13 more
Scores
EPSS
0.0062
EPSS Percentile
70.1%
Details
CWE
CWE-20
Status
published
Products (6)
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
8.04
canonical/ubuntu_linux
9.10
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
10.10
php/php
< 5.2.14
Published
Nov 12, 2010
Tracked Since
Feb 18, 2026