lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
We have discovered 2,124 live websites that are affected by CVE-2013-4508.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 2,124 live websites (4.36% of lighttpd install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 15 versions ( 26% of all versions) |
| 289 websites | |
| 792 websites | |
| 188 websites | |
| 170 websites | |
| 108 websites | |
| 75 websites | |
| 58 websites | |
| 50 websites | |
| 45 websites | |
| 45 websites |
| .com | 524 websites |
| .fr | 492 websites |
| .net | 307 websites |
| .cz | 142 websites |
| .de | 99 websites |
| .org | 96 websites |
| .ru | 42 websites |
| .eu | 31 websites |
| .nl | 27 websites |
| .pl | 26 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.****.cz | **,*** | ||
| ********.com | ***,*** | ||
| ***.*********.com | ***,*** | ||
| *****.net | ***,*** | ||
| *********.********.pm | ***,*** | ||
| ***.****.fr | ***,*** | ||
| *************.********.pm | ***,*** | ||
| ***.cz | ***,*** | ||
| ********.net | ***,*** | ||
| *****.**************.de | ***,*** |