← Back

CVE-2002-1316

nvd nist
Published: Nov 29, 2002Modified: Apr 16, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).

Affected (12)

1 product
Iplanet Web Server
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Iplanet
Version 4.1
Version 4.1_sp10
Version 4.1_sp11
Version 4.1_sp1
Version 4.1_sp2
Version 4.1_sp3
Version 4.1_sp4
Version 4.1_sp5
Version 4.1_sp6
Version 4.1_sp7
Version 4.1_sp8
Version 4.1_sp9

References (12)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.