6.8

CVE-2002-1315

Exploit

Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IplanetIplanet Web Server Version4.1
IplanetIplanet Web Server Version4.1_sp1
IplanetIplanet Web Server Version4.1_sp2
IplanetIplanet Web Server Version4.1_sp3
IplanetIplanet Web Server Version4.1_sp4
IplanetIplanet Web Server Version4.1_sp5
IplanetIplanet Web Server Version4.1_sp6
IplanetIplanet Web Server Version4.1_sp7
IplanetIplanet Web Server Version4.1_sp8
IplanetIplanet Web Server Version4.1_sp9
IplanetIplanet Web Server Version4.1_sp10
IplanetIplanet Web Server Version4.1_sp11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.08% 0.823
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P