CVE-2001-0835
Last modified
CVE-2001-0835 is a vulnerability of currently unknown severity. Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.. EPSS estimates a 2.67% chance of exploitation in the next 30 days.
Description
Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bradford Barrett | Webalizer | <= 2.0.6 |
References
- http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.htmlPatch, Vendor Advisory
- http://www.mrunix.net/webalizer/news.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2001-141.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/3473Patch, Vendor Advisory
- http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.htmlPatch, Vendor Advisory
- http://www.mrunix.net/webalizer/news.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2001-141.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/3473Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0835?
How severe is CVE-2001-0835?
How do I fix CVE-2001-0835?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-0829A cross-site scripting vulnerability in Apache Tomcat 3.2.1 …
- CVE-2001-08306tunnel 0.08 and earlier does not properly close sockets tha…7.5
- CVE-2001-0831Unknown vulnerability in Oracle Label Security in Oracle 8.1…
- CVE-2001-0832Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows l…
- CVE-2001-0833Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 all…
- CVE-2001-0834htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier a…
- CVE-2001-0836Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remot…
- CVE-2001-0837DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-…
- CVE-2001-0838Format string vulnerability in Network Solutions Rwhoisd 1.5…
- CVE-2001-0839ibillpm.pl in iBill password management system generates wea…
- CVE-2001-0840Buffer overflow in Compaq Insight Manager XE 2.1b and earlie…
- CVE-2001-0841Directory traversal vulnerability in Search.cgi in Ikonboard…
Are you affected by CVE-2001-0835?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
