CVE-2002-1315
Summary
| CVE | CVE-2002-1315 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-11-29 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316). |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Iplanet | Iplanet Web Server | 4.1 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp1 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp10 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp11 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp2 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp3 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp4 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp5 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp6 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp7 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp8 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ISS X-Force Database: iplanet-admin-log-xss (10692): iPlanet (Sun ONE) Web Server admin error log cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Exploit |
| archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit, Vendor Advisory |
| #49475: Security Vulnerabilities with Sun ONE Web Server 4.1SP11 and Earlier java.lang.NullPointerException | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| iPlanet Admin Server Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.ngsec.com | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.