The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior.
We have discovered 945,744 live websites that are affected by CVE-2015-3185.
Product | |
Category | Web Servers |
Vulnerable Domains | 945,744 live websites (29.98% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 101 versions ( 68.71% of all versions) |
![]() | 273,414 websites |
![]() | 109,312 websites |
![]() | 90,273 websites |
![]() | 54,269 websites |
![]() | 42,325 websites |
![]() | 39,667 websites |
![]() | 37,383 websites |
![]() | 24,404 websites |
![]() | 24,045 websites |
![]() | 20,848 websites |
.com | 404,967 websites |
.de | 64,753 websites |
.net | 39,347 websites |
.org | 33,202 websites |
.ru | 32,765 websites |
.nl | 28,611 websites |
.cz | 19,603 websites |
.jp | 16,450 websites |
.it | 15,216 websites |
.info | 15,011 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.***********.com | ![]() | *** | |
*********.*************.se | ![]() | *** | |
********.*********.com | ![]() | *,*** | |
******************.com | ![]() | *,*** | |
*********.******.net | ![]() | *,*** | |
****.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
****.**.pl | ![]() | *,*** | |
******.com | ![]() | *,*** | |
********.********.de | ![]() | *,*** |
FAQ