PT-2002-2256 · Oracle · Iplanet Web Server
Publicado
2002-11-21
·
Atualizado
2016-10-18
·
CVE-2002-1315
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
iPlanet WebServer versions 4.x up to SP11
Description:
A cross-site scripting (XSS) issue allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs. This could potentially be used to escalate privileges when combined with another issue.
Recommendations:
For iPlanet WebServer versions 4.x up to SP11, consider disabling access to error logs to minimize the risk of exploitation until a fix is available. Restrict administrative access to the server to reduce the potential impact of this issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iplanet Web Server