PT-2010-1171 · Php+1 · Php+1

Published

2010-11-12

·

Updated

2023-02-13

·

CVE-2010-3870

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.4
Description The issue arises from the utf8 decode function not properly handling non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data. This makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string. The vulnerability can be exploited to conduct XSS attacks.
Recommendations For PHP versions prior to 5.3.4, update to version 5.3.4 or later to resolve the issue. As a temporary workaround, consider implementing additional input validation and sanitization to minimize the risk of exploitation. Restrict the use of the utf8 decode function until a patch is applied.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-02600
CVE-2010-3870
DSA-2195-1
RHSA-2010:0919
RHSA-2010_0919
RHSA-2011:0195
RHSA-2011_0195

Affected Products

Php
Red Hat