CVE-2009-1195

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.


We have discovered 177,651 live websites that are affected by CVE-2009-1195.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains177,651 live websites (5.63% of Apache install base)
Vulnerable Versions
  • from 0 before 2.2.11
Vulnerable Versions Count62 versions ( 42.18% of all versions)



Details

  • Published - May 29, 2009
  • Updated - Aug 7, 2024

CVE-2009-1195 usage by Country

United States18,302 websites



Taiwan97,762 websites
Germany14,352 websites
Japan9,233 websites
Singapore3,852 websites
France3,161 websites
Russia2,880 websites
Canada1,953 websites
Italy1,928 websites
Czech Republic1,911 websites

CVE-2009-1195 usage by TLD

.com104,721 websites
.de12,631 websites
.info8,019 websites
.net5,998 websites
.org4,217 websites
.cn3,548 websites
.ru2,543 websites
.jp2,501 websites
.cz1,661 websites
.at1,509 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2009-1195

Top websites that are affected by CVE-2009-1195. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.********.de Germany*,***
**********.com United States*,***
****.**********.com United States*,***
*****.**********.com United States*,***
*****.***.tw Taiwan*,***
*******.****************.com United States*,***
*******.**********.com United States*,***
***.************.de Germany*,***
******.****.br Brazil*,***
**********.***.com United States*,***
See full domain list

FAQ

A total of 177,651 websites have been identified as vulnerable to CVE-2009-1195, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2009-1195 vulnerability.
Apache versions before 2.2.11 are vulnerable to CVE-2009-1195.
Version 2.2.11 of Apache addresses the CVE-2009-1195 security vulnerability.

References