CVE-2002-1315
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly…
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- iplanet/iplanet web server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.htmlExploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=103772308030269&w=2
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-49475-1
- http://www.iss.net/security_center/static/10692.phpExploit
- http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txtExploit, Vendor Advisory
- http://www.securityfocus.com/bid/6202Exploit
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.htmlExploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=103772308030269&w=2
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-49475-1
- http://www.iss.net/security_center/static/10692.phpExploit
- http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txtExploit, Vendor Advisory
- http://www.securityfocus.com/bid/6202Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.