mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
We have discovered 324,700 live websites that are affected by CVE-2013-1896.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 324,700 live websites (12% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 50 versions ( 42% of all versions) |
| 40,341 websites | |
| 103,481 websites | |
| 31,165 websites | |
| 19,184 websites | |
| 14,574 websites | |
| 9,591 websites | |
| 9,416 websites | |
| 7,599 websites | |
| 7,483 websites | |
| 7,405 websites |
| .com | 149,580 websites |
| .de | 24,620 websites |
| .net | 12,726 websites |
| .ru | 12,652 websites |
| .org | 9,212 websites |
| .info | 9,080 websites |
| .cz | 7,742 websites |
| .jp | 5,973 websites |
| .it | 5,845 websites |
| .nl | 5,045 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| *********.******.net | *,*** | ||
| ****.**.pl | *,*** | ||
| ******.com | *,*** | ||
| ********.********.de | *,*** | ||
| ******.****************.com | *,*** | ||
| **********.com | *,*** | ||
| ******.**.pl | *,*** | ||
| ****.**********.com | *,*** | ||
| *****.**********.com | *,*** |