PT-2001-2003 · Mandrake · Webalizer
Publicado
2001-11-22
·
Atualizado
2017-12-19
·
CVE-2001-0835
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Webalizer versions 2.01 through 2.06
Description
A cross-site scripting issue allows remote attackers to inject arbitrary HTML tags into the system. This can be achieved by specifying the tags in search keywords embedded in HTTP referrer information or in host names retrieved via a reverse DNS lookup.
Recommendations
For Webalizer versions 2.01 through 2.06, consider restricting access to the referrer information and limiting the ability to inject arbitrary HTML tags in host names until a patch is available. As a temporary workaround, disabling the feature to display referrer information and host names may help minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Webalizer