6.8

CVE-2002-1316

Exploit

importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).

Data is provided by the National Vulnerability Database (NVD)
IplanetIplanet Web Server Version4.1
IplanetIplanet Web Server Version4.1_sp1
IplanetIplanet Web Server Version4.1_sp2
IplanetIplanet Web Server Version4.1_sp3
IplanetIplanet Web Server Version4.1_sp4
IplanetIplanet Web Server Version4.1_sp5
IplanetIplanet Web Server Version4.1_sp6
IplanetIplanet Web Server Version4.1_sp7
IplanetIplanet Web Server Version4.1_sp8
IplanetIplanet Web Server Version4.1_sp9
IplanetIplanet Web Server Version4.1_sp10
IplanetIplanet Web Server Version4.1_sp11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.35% 0.783
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P