PT-2001-2003 · Mandrake · Webalizer

Published

2001-11-22

·

Updated

2017-12-19

·

CVE-2001-0835

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Webalizer versions 2.01 through 2.06
Description A cross-site scripting issue allows remote attackers to inject arbitrary HTML tags into the system. This can be achieved by specifying the tags in search keywords embedded in HTTP referrer information or in host names retrieved via a reverse DNS lookup.
Recommendations For Webalizer versions 2.01 through 2.06, consider restricting access to the referrer information and limiting the ability to inject arbitrary HTML tags in host names until a patch is available. As a temporary workaround, disabling the feature to display referrer information and host names may help minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0835

Affected Products

Webalizer