The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.
We have discovered 177,651 live websites that are affected by CVE-2009-1195.
Product | |
Category | Web Servers |
Vulnerable Domains | 177,651 live websites (5.63% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 62 versions ( 42.18% of all versions) |
![]() | 18,302 websites |
![]() | 97,762 websites |
![]() | 14,352 websites |
![]() | 9,233 websites |
![]() | 3,852 websites |
![]() | 3,161 websites |
![]() | 2,880 websites |
![]() | 1,953 websites |
![]() | 1,928 websites |
![]() | 1,911 websites |
.com | 104,721 websites |
.de | 12,631 websites |
.info | 8,019 websites |
.net | 5,998 websites |
.org | 4,217 websites |
.cn | 3,548 websites |
.ru | 2,543 websites |
.jp | 2,501 websites |
.cz | 1,661 websites |
.at | 1,509 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.********.de | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
****.**********.com | ![]() | *,*** | |
*****.**********.com | ![]() | *,*** | |
*****.***.tw | ![]() | *,*** | |
*******.****************.com | ![]() | *,*** | |
*******.**********.com | ![]() | *,*** | |
***.************.de | ![]() | *,*** | |
******.****.br | ![]() | *,*** | |
**********.***.com | ![]() | *,*** |
FAQ