6.8
CVSSv2

CVE-2002-1316

Published: 29/11/2002 Updated: 18/10/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote malicious users to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).

Vulnerable Product Search on Vulmon Subscribe to Product

iplanet iplanet web server 4.1_sp4

iplanet iplanet web server 4.1

iplanet iplanet web server 4.1_sp6

iplanet iplanet web server 4.1_sp7

iplanet iplanet web server 4.1_sp11

iplanet iplanet web server 4.1_sp2

iplanet iplanet web server 4.1_sp3

iplanet iplanet web server 4.1_sp5

iplanet iplanet web server 4.1_sp1

iplanet iplanet web server 4.1_sp10

iplanet iplanet web server 4.1_sp8

iplanet iplanet web server 4.1_sp9