6.8

CVE-2002-1315

Exploit
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iplanet ≫ Iplanet Web Server Version 4.1
Iplanet ≫ Iplanet Web Server Version 4.1_sp1
Iplanet ≫ Iplanet Web Server Version 4.1_sp2
Iplanet ≫ Iplanet Web Server Version 4.1_sp3
Iplanet ≫ Iplanet Web Server Version 4.1_sp4
Iplanet ≫ Iplanet Web Server Version 4.1_sp5
Iplanet ≫ Iplanet Web Server Version 4.1_sp6
Iplanet ≫ Iplanet Web Server Version 4.1_sp7
Iplanet ≫ Iplanet Web Server Version 4.1_sp8
Iplanet ≫ Iplanet Web Server Version 4.1_sp9
Iplanet ≫ Iplanet Web Server Version 4.1_sp10
Iplanet ≫ Iplanet Web Server Version 4.1_sp11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.64% 0.733
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html
Vendor Advisory
Exploit
http://marc.info/?l=bugtraq&m=103772308030269&w=2
http://sunsolve.sun.com/search/document.do?assetkey=1-26-49475-1
http://www.iss.net/security_center/static/10692.php
Exploit
http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/6202
Exploit