I just checked one of my web-servers with nikto and ist says: ... + /webalizer/ - Webalizer may be installed. Versions lower than 2.10-09 vulnerable to Cross Site Scripting (XSS). CA-2000-02. (GET) ... Since the current version on the webalizer home page is 2.01-10 I think the version number in this warning has transposed digits and should be 2.01-09. Reproducible: Always Steps to Reproduce: nikto -h webserver (where webalizer is installed on webserver)
This is not a right place to fix this issue, see http://www.cirt.net/submit.shtml or contact the author directly (see README).
OK. I sent an email to the author.