mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
We have discovered 459,428 live websites that are affected by CVE-2013-2249.
Product | |
Category | Web Servers |
Vulnerable Domains | 459,428 live websites (14.56% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 93 versions ( 63.27% of all versions) |
![]() | 82,022 websites |
![]() | 105,414 websites |
![]() | 41,633 websites |
![]() | 32,171 websites |
![]() | 20,705 websites |
![]() | 16,013 websites |
![]() | 12,667 websites |
![]() | 12,546 websites |
![]() | 12,357 websites |
![]() | 11,069 websites |
.com | 202,859 websites |
.de | 32,140 websites |
.net | 19,952 websites |
.ru | 17,856 websites |
.org | 15,379 websites |
.jp | 10,575 websites |
.cz | 10,364 websites |
.info | 10,159 websites |
.nl | 7,086 websites |
.it | 6,789 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***********.com | ![]() | *** | |
*********.******.net | ![]() | *,*** | |
****.**.pl | ![]() | *,*** | |
******.com | ![]() | *,*** | |
********.********.de | ![]() | *,*** | |
******.****************.com | ![]() | *,*** | |
****.***********.de | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
****.**********.com | ![]() | *,*** | |
*****.**********.com | ![]() | *,*** |
FAQ