Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.
We have discovered 538 live websites that are affected by CVE-2005-3656.
| Product | |
| Category | Web Server Extensions |
| Vulnerable Domains | 538 live websites (100% of mod_auth_pgsql install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 3 versions ( 75% of all versions) |
| 47 websites | |
| 239 websites | |
| 89 websites | |
| 39 websites | |
| 16 websites | |
| 13 websites | |
| 12 websites | |
| 12 websites | |
| 12 websites | |
| 9 websites |
| .com | 146 websites |
| .jp | 90 websites |
| .pl | 34 websites |
| .co.jp | 26 websites |
| .org | 17 websites |
| .net | 17 websites |
| .ru | 12 websites |
| .cz | 7 websites |
| .de | 6 websites |
| .fr | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.*************.**.jp | ***,*** | ||
| ********.com | ***,*** | ||
| ******************.**.hu | ***,*** | ||
| ****.jp | ***,*** | ||
| **************.com | ***,*** | ||
| ********.jp | ***,*** | ||
| ************.jp | *,***,*** | ||
| ****.*******.org | *,***,*** | ||
| *****.jp | *,***,*** | ||
| ******.jp | *,***,*** |
FAQ