Back

MEDIUM

php: XSS mitigation bypass via utf8_decode()

Published Nov 12, 2010

Description

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (37)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 12, 2010
Updated Aug 7, 2024
Reserved Oct 8, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Sep 27, 2009