The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
We have discovered 613,773 live websites that are affected by CVE-2013-6438.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 613,773 live websites (23% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 68 versions ( 57% of all versions) |
| 150,507 websites | |
| 109,352 websites | |
| 42,718 websites | |
| 42,150 websites | |
| 24,795 websites | |
| 21,432 websites | |
| 20,685 websites | |
| 17,775 websites | |
| 15,510 websites | |
| 14,628 websites |
| .com | 286,434 websites |
| .de | 30,203 websites |
| .net | 24,407 websites |
| .ru | 21,139 websites |
| .org | 20,719 websites |
| .nl | 15,527 websites |
| .it | 12,389 websites |
| .jp | 12,371 websites |
| .info | 11,757 websites |
| .cz | 11,640 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.***********.com | *** | ||
| ******************.com | *,*** | ||
| *********.******.net | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| ****.**.pl | *,*** | ||
| ******.com | *,*** | ||
| ********.********.de | *,*** | ||
| ******.****************.com | *,*** | ||
| *.******.***.***.br | *,*** |