CVE-2013-1896

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.


We have discovered 324,700 live websites that are affected by CVE-2013-1896.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains324,700 live websites (12% of Apache install base)
Vulnerable Versions
  • from 0 through 2.2.25
Vulnerable Versions Count50 versions ( 42% of all versions)



Details

  • Published - Jul 11, 2013
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2013-1896
United States40,341 websites



Taiwan103,481 websites
Germany31,165 websites
Japan19,184 websites
Russia14,574 websites
France9,591 websites
Czech Republic9,416 websites
Korea, South7,599 websites
Italy7,483 websites
Netherlands7,405 websites

Website Distribution by TLD

Number of websites using CVE-2013-1896
.com149,580 websites
.de24,620 websites
.net12,726 websites
.ru12,652 websites
.org9,212 websites
.info9,080 websites
.cz7,742 websites
.jp5,973 websites
.it5,845 websites
.nl5,045 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-1896

Top websites that are affected by CVE-2013-1896. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.******.net United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
**********.com United States*,***
******.**.pl France*,***
****.**********.com United States*,***
*****.**********.com United States*,***
See full domain list

FAQ

A total of 324,700 websites have been identified as vulnerable to CVE-2013-1896, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2013-1896 vulnerability.
Apache versions up to and including 2.2.25 are vulnerable to CVE-2013-1896.

References