The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
We have discovered 866,995 live websites that are affected by CVE-2013-6438.
Product | |
Category | Web Servers |
Vulnerable Domains | 866,995 live websites (27.48% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 96 versions ( 65.31% of all versions) |
![]() | 260,788 websites |
![]() | 109,136 websites |
![]() | 71,534 websites |
![]() | 53,677 websites |
![]() | 37,783 websites |
![]() | 34,693 websites |
![]() | 28,776 websites |
![]() | 23,311 websites |
![]() | 19,798 websites |
![]() | 18,510 websites |
.com | 383,789 websites |
.de | 53,077 websites |
.net | 36,102 websites |
.org | 30,561 websites |
.ru | 30,414 websites |
.nl | 27,569 websites |
.jp | 16,188 websites |
.cz | 15,055 websites |
.info | 14,496 websites |
.it | 13,736 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***********.com | ![]() | *** | |
*********.*************.se | ![]() | *** | |
********.*********.com | ![]() | *,*** | |
******************.com | ![]() | *,*** | |
*********.******.net | ![]() | *,*** | |
****.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
****.**.pl | ![]() | *,*** | |
******.com | ![]() | *,*** | |
********.********.de | ![]() | *,*** |
FAQ