CVE-2013-1896

mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.


We have discovered 397,510 live websites that are affected by CVE-2013-1896.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains397,510 live websites (12.60% of Apache install base)
Vulnerable Versions
  • from 0 before 2.2.25
Vulnerable Versions Count77 versions ( 52.38% of all versions)



Details

  • Published - Jul 11, 2013
  • Updated - Aug 6, 2024

CVE-2013-1896 usage by Country

United States56,052 websites



Taiwan105,094 websites
Germany38,673 websites
Japan25,142 websites
Russia17,192 websites
France14,693 websites
Czech Republic11,822 websites
GB11,483 websites
Netherlands9,923 websites
Korea, South9,383 websites

CVE-2013-1896 usage by TLD

.com174,913 websites
.de30,315 websites
.net16,683 websites
.ru14,951 websites
.org12,463 websites
.info9,777 websites
.cz9,621 websites
.jp7,985 websites
.nl6,445 websites
.it6,319 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-1896

Top websites that are affected by CVE-2013-1896. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.******.net United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
****.***********.de Germany*,***
**********.com United States*,***
****.**********.com United States*,***
*****.**********.com United States*,***
See full domain list

FAQ

A total of 397,510 websites have been identified as vulnerable to CVE-2013-1896, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2013-1896 vulnerability.
Apache versions before 2.2.25 are vulnerable to CVE-2013-1896.
Version 2.2.25 of Apache addresses the CVE-2013-1896 security vulnerability.

References