Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2002-1316


importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).


Published

2002-11-29T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application iplanet iplanet_web_server 4.1 Yes
Application iplanet iplanet_web_server 4.1_sp1 Yes
Application iplanet iplanet_web_server 4.1_sp2 Yes
Application iplanet iplanet_web_server 4.1_sp3 Yes
Application iplanet iplanet_web_server 4.1_sp4 Yes
Application iplanet iplanet_web_server 4.1_sp5 Yes
Application iplanet iplanet_web_server 4.1_sp6 Yes
Application iplanet iplanet_web_server 4.1_sp7 Yes
Application iplanet iplanet_web_server 4.1_sp8 Yes
Application iplanet iplanet_web_server 4.1_sp9 Yes
Application iplanet iplanet_web_server 4.1_sp10 Yes
Application iplanet iplanet_web_server 4.1_sp11 Yes

References