php: XSS and SQL injection bypass via crafted overlong UTF-8 encoded string
Published Nov 12, 2010
6.8
MEDIUMCVSS 2.0
EPSS 2.65%
Description
Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.
Affected products
No data.
- ≤ 5.2.10
- 1.0
- 2.0
- 2.0b10
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.5
- 4.0.6
- 4.0.7
- 4.1.0
- 4.1.1
- 4.1.2
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.3.8
- 4.3.9
- 4.3.10
- 4.3.11
- 4.4.0
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.5
- 4.4.6
- 4.4.7
- 4.4.8
- 4.4.9
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.1.0
- 5.1.1
- 5.1.2
- 5.1.3
- 5.1.4
- 5.1.5
- 5.1.6
- 5.2.0
- 5.2.1
No data.
Red Hat Enterprise Linux 4
php-0:4.3.9-3.31
Fixed · RHSA-2010:0919
Red Hat Enterprise Linux 5
php-0:5.1.6-27.el5_5.3
Fixed · RHSA-2010:0919
Red Hat Enterprise Linux 6
php-0:5.3.2-6.el6_0.1
Fixed · RHSA-2011:0195
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | php-0:4.3.9-3.31 | Fixed | RHSA-2010:0919 |
| Red Hat Enterprise Linux 5 | php-0:5.1.6-27.el5_5.3 | Fixed | RHSA-2010:0919 |
| Red Hat Enterprise Linux 6 | php-0:5.3.2-6.el6_0.1 | Fixed | RHSA-2011:0195 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.65% (0.02652) | 85.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.65% (0.02652) | 83.62th | v5 (v2026.06.15) |
| Dec 28, 2025 | 3.45% (0.03454) | 87.15th | v4 (v2025.03.14) |
| Dec 27, 2025 | 0.67% (0.00669) | 70.75th | v4 (v2025.03.14) |
| Dec 6, 2025 | 3.45% (0.03454) | 87.09th | v4 (v2025.03.14) |
| Oct 28, 2025 | 4.62% (0.04618) | 88.75th | v4 (v2025.03.14) |
| Oct 27, 2025 | 0.67% (0.00669) | 70.56th | v4 (v2025.03.14) |
| Oct 15, 2025 | 4.62% (0.04618) | 88.73th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.21% (0.02209) | 74.03th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.85% (0.03852) | 87.42th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.64% (0.00637) | 79.83th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.64% (0.00637) | 78.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.64% (0.00637) | 75.87th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (19)
- http://bugs.php.net/bug.php?id=49687 x_refsource_CONFIRMExploit
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052836.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052845.html vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/42410 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42812 third-party-advisoryx_refsource_SECUNIA
- http://sirdarckcat.blogspot.com/2009/10/couple-of-unicode-issues-on-php-and.html x_refsource_MISCExploit
- http://www.blackhat.com/presentations/bh-usa-09/VELANAVA/BHUSA09-VelaNava-FavoriteXSS-SLIDES.pdf x_refsource_MISCExploit
- http://www.redhat.com/support/errata/RHSA-2010-0919.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2011-0195.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/44889 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1042-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2010/3081 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0020 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0021 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0077 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-5016 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=652836 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-5016
- https://www.cve.org/CVERecord?id=CVE-2009-5016
Change history (0)
No recorded changes yet.