PT-2001-2003 · Mandrake · Webalizer
Published
2001-11-22
·
Updated
2017-12-19
·
CVE-2001-0835
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Webalizer versions 2.01 through 2.06
Description
A cross-site scripting issue allows remote attackers to inject arbitrary HTML tags into the system. This can be achieved by specifying the tags in search keywords embedded in HTTP referrer information or in host names retrieved via a reverse DNS lookup.
Recommendations
For Webalizer versions 2.01 through 2.06, consider restricting access to the referrer information and limiting the ability to inject arbitrary HTML tags in host names until a patch is available. As a temporary workaround, disabling the feature to display referrer information and host names may help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webalizer