CNCVE编号:CNCVE-20010835 CVE编号:CAN-2001-0835 安全级别:高 漏洞中文描述: Webalizer 2.01-06也可能使其他版本中的交叉站点脚本漏洞允许远程攻击者通过把任意HTML标签列入(1)植入HTTP参考信息中的搜索口令之中或(2)通过逆DNS检查检索到的主机名之中来嵌入任意HTML标签。 漏洞英文描述: Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrievaled to attach any Html ticket. 漏洞参考: Reference: BUGTRAQ:20011024 Cross-site Scripting Flaw in webalizer Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100394630702875&w=2 Reference: CONFIRM:http://www.mrunix.net/webalizer/news.html Reference: SUSE:SuSE-SA:2001:040 Reference: 系统类型: Apple 漏洞类型:输入有效性检查错误