mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
We have discovered 397,510 live websites that are affected by CVE-2013-1896.
Product | |
Category | Web Servers |
Vulnerable Domains | 397,510 live websites (12.60% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 77 versions ( 52.38% of all versions) |
![]() | 56,052 websites |
![]() | 105,094 websites |
![]() | 38,673 websites |
![]() | 25,142 websites |
![]() | 17,192 websites |
![]() | 14,693 websites |
![]() | 11,822 websites |
![]() | 11,483 websites |
![]() | 9,923 websites |
![]() | 9,383 websites |
.com | 174,913 websites |
.de | 30,315 websites |
.net | 16,683 websites |
.ru | 14,951 websites |
.org | 12,463 websites |
.info | 9,777 websites |
.cz | 9,621 websites |
.jp | 7,985 websites |
.nl | 6,445 websites |
.it | 6,319 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***********.com | ![]() | *** | |
*********.******.net | ![]() | *,*** | |
****.**.pl | ![]() | *,*** | |
******.com | ![]() | *,*** | |
********.********.de | ![]() | *,*** | |
******.****************.com | ![]() | *,*** | |
****.***********.de | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
****.**********.com | ![]() | *,*** | |
*****.**********.com | ![]() | *,*** |
FAQ