CVE-2003-1577
Summary
| CVE | CVE-2003-1577 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-05 22:30:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer, via an HTTP request in conjunction with a crafted DNS response, related to an "Inverse Lookup Log Corruption (ILLC)" issue, a different vulnerability than CVE-2002-1315 and CVE-2002-1316. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | One Web Server | 4.1 | All | All | All |
| Application | Sun | One Web Server | 4.1 | sp1 | All | All |
| Application | Sun | One Web Server | 4.1 | sp10 | All | All |
| Application | Sun | One Web Server | 4.1 | sp11 | All | All |
| Application | Sun | One Web Server | 4.1 | sp2 | All | All |
| Application | Sun | One Web Server | 4.1 | sp3 | All | All |
| Application | Sun | One Web Server | 4.1 | sp4 | All | All |
| Application | Sun | One Web Server | 4.1 | sp5 | All | All |
| Application | Sun | One Web Server | 4.1 | sp6 | All | All |
| Application | Sun | One Web Server | 4.1 | sp7 | All | All |
| Application | Sun | One Web Server | 4.1 | sp8 | All | All |
| Application | Sun | One Web Server | 4.1 | sp9 | All | All |
| Application | Sun | One Web Server | 6.0 | All | All | All |
| Application | Sun | One Web Server | 6.0 | sp1 | All | All |
| Application | Sun | One Web Server | 6.0 | sp2 | All | All |
| Application | Sun | One Web Server | 6.0 | sp3 | All | All |
| Application | Sun | One Web Server | 6.0 | sp4 | All | All |
| Application | Sun | One Web Server | All | sp12 | All | All |
| Application | Sun | One Web Server | All | sp5 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.