CVE-2013-6438

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.


We have discovered 613,773 live websites that are affected by CVE-2013-6438.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains613,773 live websites (23% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.8
Vulnerable Versions Count68 versions ( 57% of all versions)



Details

  • Published - Mar 18, 2014
  • Updated - Aug 6, 2024

Website Distribution by Country

Number of websites using CVE-2013-6438
United States150,507 websites



Taiwan109,352 websites
Japan42,718 websites
Germany42,150 websites
Russia24,795 websites
Netherlands21,432 websites
Singapore20,685 websites
France17,775 websites
Italy15,510 websites
Korea, South14,628 websites

Website Distribution by TLD

Number of websites using CVE-2013-6438
.com286,434 websites
.de30,203 websites
.net24,407 websites
.ru21,139 websites
.org20,719 websites
.nl15,527 websites
.it12,389 websites
.jp12,371 websites
.info11,757 websites
.cz11,640 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2013-6438

Top websites that are affected by CVE-2013-6438. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***********.com Canada***
******************.com United States*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
****.**.pl Poland*,***
******.com Japan*,***
********.********.de Germany*,***
******.****************.com United States*,***
*.******.***.***.br Brazil*,***
See full domain list

FAQ

A total of 613,773 websites have been identified as vulnerable to CVE-2013-6438, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2013-6438 vulnerability.
Apache versions up to and including 2.4.8 are vulnerable to CVE-2013-6438.

References