CVE-2013-1862

mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.


We have discovered 273,005 live websites that are affected by CVE-2013-1862.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains273,005 live websites (11% of Apache install base)
Vulnerable Versions
  • from 2.2 through 2.2.25
Vulnerable Versions Count22 versions ( 18% of all versions)



Details

  • Published - Jun 10, 2013
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2013-1862
United States28,359 websites



Taiwan102,596 websites
Germany26,688 websites
Japan12,388 websites
Russia11,160 websites
Czech Republic7,967 websites
France7,054 websites
Italy6,504 websites
Netherlands6,261 websites
Korea, South6,047 websites

Website Distribution by TLD

Number of websites using CVE-2013-1862
.com131,479 websites
.de21,419 websites
.ru9,677 websites
.net8,925 websites
.info8,618 websites
.org6,604 websites
.cz6,513 websites
.it5,205 websites
.nl4,400 websites
.jp4,374 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-1862

Top websites that are affected by CVE-2013-1862. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.******.net United States*,***
****.**.pl Poland*,***
******.com Japan*,***
******.****************.com United States*,***
******.**.pl France*,***
*****.***.tw Taiwan*,***
*******.****************.com United States*,***
******.****.br Brazil*,***
*********.com GB*,***
See full domain list

FAQ

A total of 273,005 websites have been identified as vulnerable to CVE-2013-1862, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2013-1862 vulnerability.
Apache versions up to 2.2.25 are vulnerable to CVE-2013-1862.
CVE-2013-1862 is resolved in version 2.2.25 of Apache.

References