VYPR

Webalizer

by Bradford Barrett

CVEs (2)

  • CVE-2002-0180Apr 22, 2002
    risk 0.00cvss epss 0.04

    Buffer overflow in Webalizer 2.01-06, when configured to use reverse DNS lookups, allows remote attackers to execute arbitrary code by connecting to the monitored web server from an IP address that resolves to a long hostname.

  • CVE-2001-0835Dec 6, 2001
    risk 0.00cvss epss 0.03

    Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS…