The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
We have discovered 437,247 live websites that are affected by CVE-2009-1890.
Product | |
Category | Web Servers |
Vulnerable Domains | 437,247 live websites (13.86% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 88 versions ( 59.86% of all versions) |
![]() | 69,583 websites |
![]() | 105,389 websites |
![]() | 40,032 websites |
![]() | 32,075 websites |
![]() | 19,829 websites |
![]() | 15,766 websites |
![]() | 12,263 websites |
![]() | 12,138 websites |
![]() | 11,765 websites |
![]() | 10,612 websites |
.com | 191,308 websites |
.de | 31,346 websites |
.net | 19,242 websites |
.ru | 17,176 websites |
.org | 14,131 websites |
.jp | 10,515 websites |
.info | 10,092 websites |
.cz | 9,997 websites |
.nl | 6,745 websites |
.it | 6,652 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***********.com | ![]() | *** | |
*********.******.net | ![]() | *,*** | |
****.**.pl | ![]() | *,*** | |
******.com | ![]() | *,*** | |
********.********.de | ![]() | *,*** | |
******.****************.com | ![]() | *,*** | |
****.***********.de | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
****.**********.com | ![]() | *,*** | |
*****.**********.com | ![]() | *,*** |
FAQ