Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2002-1315


Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).


Published

2002-11-29T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application iplanet iplanet_web_server 4.1 Yes
Application iplanet iplanet_web_server 4.1_sp1 Yes
Application iplanet iplanet_web_server 4.1_sp2 Yes
Application iplanet iplanet_web_server 4.1_sp3 Yes
Application iplanet iplanet_web_server 4.1_sp4 Yes
Application iplanet iplanet_web_server 4.1_sp5 Yes
Application iplanet iplanet_web_server 4.1_sp6 Yes
Application iplanet iplanet_web_server 4.1_sp7 Yes
Application iplanet iplanet_web_server 4.1_sp8 Yes
Application iplanet iplanet_web_server 4.1_sp9 Yes
Application iplanet iplanet_web_server 4.1_sp10 Yes
Application iplanet iplanet_web_server 4.1_sp11 Yes

References