CVE-2013-6438

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.


We have discovered 866,995 live websites that are affected by CVE-2013-6438.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains866,995 live websites (27.48% of Apache install base)
Vulnerable Versions
  • from 0 before 2.4.8
Vulnerable Versions Count96 versions ( 65.31% of all versions)



Details

  • Published - Mar 18, 2014
  • Updated - Aug 6, 2024

CVE-2013-6438 usage by Country

United States260,788 websites



Taiwan109,136 websites
Germany71,534 websites
Japan53,677 websites
Netherlands37,783 websites
Russia34,693 websites
France28,776 websites
Singapore23,311 websites
GB19,798 websites
Czech Republic18,510 websites

CVE-2013-6438 usage by TLD

.com383,789 websites
.de53,077 websites
.net36,102 websites
.org30,561 websites
.ru30,414 websites
.nl27,569 websites
.jp16,188 websites
.cz15,055 websites
.info14,496 websites
.it13,736 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-6438

Top websites that are affected by CVE-2013-6438. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
*********.*************.se United States***
********.*********.com Singapore*,***
******************.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
See full domain list

FAQ

A total of 866,995 websites have been identified as vulnerable to CVE-2013-6438, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2013-6438 vulnerability.
Apache versions before 2.4.8 are vulnerable to CVE-2013-6438.
Version 2.4.8 of Apache addresses the CVE-2013-6438 security vulnerability.

References