Back

CVE-2001-0835

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

Published: Dec 6, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
bradford_barrett webalizer *

GitHub Security Advisory GHSA-49cp-mq89-xq82

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.38%

Top 12% most likely to be exploited

Threat Score 31 / 100

Data Sources

NVD EPSS GitHub