CVE-2013-4508

lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.


We have discovered 2,124 live websites that are affected by CVE-2013-4508.

Run a Free Instant Scan




Affected Software

Product  lighttpd
Category Web Servers
Vulnerable Domains2,124 live websites (4.36% of lighttpd install base)
Vulnerable Versions
  • from 0 through 1.4.34
Vulnerable Versions Count15 versions ( 26% of all versions)



Details

  • Published - Nov 8, 2013
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2013-4508
United States289 websites



France792 websites
Czech Republic188 websites
Germany170 websites
Singapore108 websites
GB75 websites
Poland58 websites
India50 websites
Italy45 websites
Russia45 websites

Website Distribution by TLD

Number of websites using CVE-2013-4508
.com524 websites
.fr492 websites
.net307 websites
.cz142 websites
.de99 websites
.org96 websites
.ru42 websites
.eu31 websites
.nl27 websites
.pl26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-4508

Top websites that are affected by CVE-2013-4508. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.****.cz Czech Republic**,***
********.com United States***,***
***.*********.com United States***,***
*****.net United States***,***
*********.********.pm United States***,***
***.****.fr France***,***
*************.********.pm United States***,***
***.cz Czech Republic***,***
********.net Singapore***,***
*****.**************.de Germany***,***
See full domain list

FAQ

A total of 2,124 websites have been identified as vulnerable to CVE-2013-4508, based on global website indexing conducted by WebTechSurvey.
The lighttpd is affected by the CVE-2013-4508 vulnerability.
lighttpd versions up to and including 1.4.34 are vulnerable to CVE-2013-4508.