# CVE-2001-0835

## Summary

- **CVE ID:** CVE-2001-0835
- **Severity:** UNKNOWN
- **CVSS Score:** 0.23
- **CWE:** N/A
- **Published:** Nov 22, 2001
- **Last Modified:** Mar 16, 2026

## Description

Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.securityfocus.com/bid/3473)
- [CNA](http://www.mrunix.net/webalizer/news.html)
- [CNA](http://www.redhat.com/support/errata/RHSA-2001-141.html)
- [CNA](http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.html)
- [CNA](http://www.linuxsecurity.com/advisories/other_advisory-1677.html)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/7351)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/7350)
- [CNA](http://www.redhat.com/support/errata/RHSA-2001-140.html)
- [CNA](http://marc.info/?l=bugtraq&m=100394630702875&w=2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 4.69%
- **EPSS Percentile:** 89.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._