SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-1316

importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a…

MEDIUM 6.8EPSS 2.04%

Does this matter?

Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.

Description

importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.04% probability · 80th percentile
CISA KEV
Not listed
Affected
iplanet/iplanet web server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.