4.3

CVE-2003-1578

Exploit

Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

Data is provided by the National Vulnerability Database (NVD)
SunOne Web Server Updatesp12 Version <= 4.1
SunOne Web Server Version4.1
SunOne Web Server Version4.1 Updatesp1
SunOne Web Server Version4.1 Updatesp10
SunOne Web Server Version4.1 Updatesp11
SunOne Web Server Version4.1 Updatesp2
SunOne Web Server Version4.1 Updatesp3
SunOne Web Server Version4.1 Updatesp4
SunOne Web Server Version4.1 Updatesp5
SunOne Web Server Version4.1 Updatesp6
SunOne Web Server Version4.1 Updatesp7
SunOne Web Server Version4.1 Updatesp8
SunOne Web Server Version4.1 Updatesp9
SunOne Web Server Updatesp5 Version <= 6.0
SunOne Web Server Version6.0
SunOne Web Server Version6.0 Updatesp1
SunOne Web Server Version6.0 Updatesp2
SunOne Web Server Version6.0 Updatesp3
SunOne Web Server Version6.0 Updatesp4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.49
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N