6.8

CVE-2007-0183

Exploit

Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Data is provided by the National Vulnerability Database (NVD)
SunIplanet Web Server Version4.1
SunIplanet Web Server Version4.1 Updatesp1
SunIplanet Web Server Version4.1 Updatesp1 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp10
SunIplanet Web Server Version4.1 Updatesp10 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp2
SunIplanet Web Server Version4.1 Updatesp2 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp3
SunIplanet Web Server Version4.1 Updatesp3 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp4
SunIplanet Web Server Version4.1 Updatesp4 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp5
SunIplanet Web Server Version4.1 Updatesp5 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp6
SunIplanet Web Server Version4.1 Updatesp6 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp7
SunIplanet Web Server Version4.1 Updatesp7 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp8
SunIplanet Web Server Version4.1 Updatesp8 Editionenterprise
SunIplanet Web Server Version4.1 Updatesp9
SunIplanet Web Server Version4.1 Updatesp9 Editionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.5% 0.887
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P