{"api_version":"1","generated_at":"2026-07-23T09:44:53+00:00","cve":"CVE-2001-0835","urls":{"html":"https://cve.report/CVE-2001-0835","api":"https://cve.report/api/cve/CVE-2001-0835.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-0835","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-0835"},"summary":{"title":"CVE-2001-0835","description":"Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-12-06 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7350","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7350","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mrunix.net/webalizer/news.html","name":"http://www.mrunix.net/webalizer/news.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"The Webalizer: Whats New","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.linuxsecurity.com/advisories/other_advisory-1677.html","name":"http://www.linuxsecurity.com/advisories/other_advisory-1677.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"LinuxSecurity.com: EnGarde:  'webalizer' cross-site scripting vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2001-140.html","name":"http://www.redhat.com/support/errata/RHSA-2001-140.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7351","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7351","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2001-141.html","name":"http://www.redhat.com/support/errata/RHSA-2001-141.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/3473","name":"http://www.securityfocus.com/bid/3473","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Bradford Barrett Webalizer Cross-Agent Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=100394630702875&w=2","name":"http://marc.info/?l=bugtraq&m=100394630702875&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.html","name":"http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SuSE Security announcements: [suse-security-announce] SuSE Secu","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-0835","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-0835","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"835","vulnerable":"1","versionEndIncluding":"2.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bradford_barrett","cpe5":"webalizer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:37:07.050Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"3473","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3473"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mrunix.net/webalizer/news.html"},{"name":"RHSA-2001:141","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2001-141.html"},{"name":"SuSE-SA:2001:040","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.html"},{"name":"ESA-20011101-01","tags":["vendor-advisory","x_refsource_ENGARDE","x_transferred"],"url":"http://www.linuxsecurity.com/advisories/other_advisory-1677.html"},{"name":"webalizer-html-tags-keywords(7351)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7351"},{"name":"webalizer-html-tag-host(7350)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7350"},{"name":"RHSA-2001:140","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2001-140.html"},{"name":"20011024 Cross-site Scripting Flaw in webalizer","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=100394630702875&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-10-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-18T21:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"3473","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3473"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mrunix.net/webalizer/news.html"},{"name":"RHSA-2001:141","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2001-141.html"},{"name":"SuSE-SA:2001:040","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.html"},{"name":"ESA-20011101-01","tags":["vendor-advisory","x_refsource_ENGARDE"],"url":"http://www.linuxsecurity.com/advisories/other_advisory-1677.html"},{"name":"webalizer-html-tags-keywords(7351)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7351"},{"name":"webalizer-html-tag-host(7350)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7350"},{"name":"RHSA-2001:140","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2001-140.html"},{"name":"20011024 Cross-site Scripting Flaw in webalizer","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=100394630702875&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-0835","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"3473","refsource":"BID","url":"http://www.securityfocus.com/bid/3473"},{"name":"http://www.mrunix.net/webalizer/news.html","refsource":"CONFIRM","url":"http://www.mrunix.net/webalizer/news.html"},{"name":"RHSA-2001:141","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2001-141.html"},{"name":"SuSE-SA:2001:040","refsource":"SUSE","url":"http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.html"},{"name":"ESA-20011101-01","refsource":"ENGARDE","url":"http://www.linuxsecurity.com/advisories/other_advisory-1677.html"},{"name":"webalizer-html-tags-keywords(7351)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7351"},{"name":"webalizer-html-tag-host(7350)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7350"},{"name":"RHSA-2001:140","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2001-140.html"},{"name":"20011024 Cross-site Scripting Flaw in webalizer","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=100394630702875&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-0835","datePublished":"2001-11-22T05:00:00.000Z","dateReserved":"2001-11-22T00:00:00.000Z","dateUpdated":"2024-08-08T04:37:07.050Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-12-06 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bradford_barrett:webalizer:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.6","matchCriteriaId":"F5701FB3-1F15-4E08-83B3-35128DE54AE3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"835","Ordinal":"1","Title":"CVE-2001-0835","CVE":"CVE-2001-0835","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"835","Ordinal":"1","NoteData":"Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.","Type":"Description","Title":"CVE-2001-0835"},{"CveYear":"2001","CveId":"835","Ordinal":"2","NoteData":"2001-11-22","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"835","Ordinal":"3","NoteData":"2017-12-18","Type":"Other","Title":"Modified"}]}}}