PT-2001-2003 · Mandrake · Webalizer

Publicado

2001-11-22

·

Atualizado

2017-12-19

·

CVE-2001-0835

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Webalizer versions 2.01 through 2.06
Description A cross-site scripting issue allows remote attackers to inject arbitrary HTML tags into the system. This can be achieved by specifying the tags in search keywords embedded in HTTP referrer information or in host names retrieved via a reverse DNS lookup.
Recommendations For Webalizer versions 2.01 through 2.06, consider restricting access to the referrer information and limiting the ability to inject arbitrary HTML tags in host names until a patch is available. As a temporary workaround, disabling the feature to display referrer information and host names may help minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0835

Produtos afetados

Webalizer