CVE-2002-1316
Summary
| CVE | CVE-2002-1316 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-11-29 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315). |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Iplanet | Iplanet Web Server | 4.1 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp1 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp10 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp11 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp2 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp3 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp4 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp5 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp6 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp7 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp8 | All | All | All |
| Application | Iplanet | Iplanet Web Server | 4.1_sp9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ISS X-Force Database: iplanet-perl-command-execution (10693): iPlanet (Sun ONE) Web Server admin Perl scripts open() command execution | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| iPlanet Admin Server Insecure Open Call Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit, Vendor Advisory |
| #49475: Security Vulnerabilities with Sun ONE Web Server 4.1SP11 and Earlier java.lang.NullPointerException | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.ngsec.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.