CVE-2002-1316: XSS
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1316?
CVE-2002-1316 is considered a high-severity vulnerability due to the ability for web administrators to execute arbitrary commands.
How do I fix CVE-2002-1316?
To fix CVE-2002-1316, upgrade to a newer, patched version of iPlanet Web Server beyond SP11.
What versions of iPlanet Web Server are affected by CVE-2002-1316?
CVE-2002-1316 affects iPlanet Web Server versions 4.1 up to SP11, including all SP versions from 1 to 11.
Can CVE-2002-1316 be exploited remotely?
Yes, CVE-2002-1316 may allow remote attackers to exploit the vulnerability through shell metacharacters in the dir parameter.
What is the relationship between CVE-2002-1316 and CVE-2002-1315?
CVE-2002-1316 may be leveraged together with CVE-2002-1315, which pertains to a cross-site scripting (XSS) issue.