PT-2010-1198 · Sun · Sun One Web Server
Publicado
2010-02-05
·
Atualizado
2017-08-17
·
CVE-2003-1578
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sun ONE (aka iPlanet) Web Server versions 4.1 through SP12
Sun ONE (aka iPlanet) Web Server versions 6.0 through SP5
Description
The issue allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
Recommendations
For Sun ONE (aka iPlanet) Web Server versions 4.1 through SP12, consider disabling DNS resolution for client IP addresses to prevent exploitation.
For Sun ONE (aka iPlanet) Web Server versions 6.0 through SP5, consider disabling DNS resolution for client IP addresses to prevent exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sun One Web Server