CVE-2013-2249

mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.


We have discovered 323,811 live websites that are affected by CVE-2013-2249.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains323,811 live websites (13% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.5
Vulnerable Versions Count66 versions ( 54% of all versions)



Details

  • Published - Jul 23, 2013
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2013-2249
United States42,028 websites



Taiwan103,021 websites
Germany28,969 websites
Japan22,581 websites
Russia14,092 websites
Korea, South8,920 websites
Czech Republic8,685 websites
France8,678 websites
Italy7,395 websites
Netherlands6,695 websites

Website Distribution by TLD

Number of websites using CVE-2013-2249
.com151,109 websites
.de22,928 websites
.net12,861 websites
.ru12,055 websites
.info9,031 websites
.org8,967 websites
.jp7,159 websites
.cz7,142 websites
.it5,775 websites
.nl4,710 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-2249

Top websites that are affected by CVE-2013-2249. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.******.net United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
**********.com United States*,***
******.**.pl France*,***
****.**********.com United States*,***
*****.**********.com United States*,***
See full domain list

FAQ

A total of 323,811 websites have been identified as vulnerable to CVE-2013-2249, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2013-2249 vulnerability.
Apache versions up to and including 2.4.5 are vulnerable to CVE-2013-2249.

References