Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 191222 - net-analyzer/nikto: Typo in warning about vulnerable webalizer version.
Summary: net-analyzer/nikto: Typo in warning about vulnerable webalizer version.
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Perl team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-09-04 09:56 UTC by Horst Prote
Modified: 2007-09-04 10:11 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Horst Prote 2007-09-04 09:56:55 UTC
I just checked one of my web-servers with nikto and ist says:
...
+ /webalizer/ - Webalizer may be installed. Versions lower than 2.10-09 vulnerable to Cross Site Scripting (XSS). CA-2000-02. (GET)
...

Since the current version on the webalizer home page is 2.01-10 I think the version number in this warning has transposed digits and should be 2.01-09.

Reproducible: Always

Steps to Reproduce:
nikto -h webserver
(where webalizer is installed on webserver)
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-09-04 10:02:23 UTC
This is not a right place to fix this issue, see http://www.cirt.net/submit.shtml or contact the author directly (see README).
Comment 2 Horst Prote 2007-09-04 10:11:45 UTC
OK. I sent an email to the author.