PT-2002-2256 · Oracle · Iplanet Web Server

Publicado

2002-11-21

·

Atualizado

2016-10-18

·

CVE-2002-1315

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: iPlanet WebServer versions 4.x up to SP11
Description: A cross-site scripting (XSS) issue allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs. This could potentially be used to escalate privileges when combined with another issue.
Recommendations: For iPlanet WebServer versions 4.x up to SP11, consider disabling access to error logs to minimize the risk of exploitation until a fix is available. Restrict administrative access to the server to reduce the potential impact of this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1315

Produtos afetados

Iplanet Web Server