CVE-2009-1195

The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.


We have discovered 127,722 live websites that are affected by CVE-2009-1195.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains127,722 live websites (5.08% of Apache install base)
Vulnerable Versions
  • from 2.2 through 2.2.11
Vulnerable Versions Count9 versions ( 7.38% of all versions)



Details

  • Published - May 28, 2009
  • Updated - Aug 7, 2024

Website Distribution by Country

Number of websites using CVE-2009-1195
United States3,557 websites



Taiwan95,666 websites
Germany10,827 websites
Japan3,699 websites
Czech Republic1,169 websites
Italy1,134 websites
France826 websites
Argentina678 websites
Hungary668 websites

Website Distribution by TLD

Number of websites using CVE-2009-1195
.com85,372 websites
.de10,116 websites
.info7,506 websites
.net1,910 websites
.org1,208 websites
.jp1,203 websites
.cz1,003 websites
.it852 websites
.co.jp774 websites
.ru504 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2009-1195

Top websites that are affected by CVE-2009-1195. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***.tw Taiwan*,***
*******.****************.com United States*,***
******.****.br Brazil*,***
*******.********.edu United States**,***
******.********.edu United States**,***
*********.org United States**,***
******.com Taiwan**,***
****.com Taiwan**,***
*****.com Taiwan**,***
******.com Taiwan**,***
See full domain list

FAQ

A total of 127,722 websites have been identified as vulnerable to CVE-2009-1195, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2009-1195 vulnerability.
Apache versions up to and including 2.2.11 are vulnerable to CVE-2009-1195.

References