First published: Thu Nov 21 2002(Updated: )
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Iplanet Iplanet Web Server | =4.1_sp8 | |
Iplanet Iplanet Web Server | =4.1 | |
Iplanet Iplanet Web Server | =4.1_sp11 | |
Iplanet Iplanet Web Server | =4.1_sp4 | |
Iplanet Iplanet Web Server | =4.1_sp2 | |
Iplanet Iplanet Web Server | =4.1_sp5 | |
Iplanet Iplanet Web Server | =4.1_sp1 | |
Iplanet Iplanet Web Server | =4.1_sp10 | |
Iplanet Iplanet Web Server | =4.1_sp7 | |
Iplanet Iplanet Web Server | =4.1_sp9 | |
Iplanet Iplanet Web Server | =4.1_sp6 | |
Iplanet Iplanet Web Server | =4.1_sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.