{"api_version":"1","generated_at":"2026-07-23T19:43:58+00:00","cve":"CVE-2002-1315","urls":{"html":"https://cve.report/CVE-2002-1315","api":"https://cve.report/api/cve/CVE-2002-1315.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1315","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1315"},"summary":{"title":"CVE-2002-1315","description":"Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).","state":"PUBLISHED","assigner":"mitre","published_at":"2002-11-29 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.iss.net/security_center/static/10692.php","name":"http://www.iss.net/security_center/static/10692.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"ISS X-Force Database: iplanet-admin-log-xss (10692): iPlanet (Sun ONE) Web Server admin error log cross-site scripting","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html","name":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-49475-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-49475-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#49475: Security Vulnerabilities with Sun ONE Web Server 4.1SP11 and Earlier java.lang.NullPointerException","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=103772308030269&w=2","name":"http://marc.info/?l=bugtraq&m=103772308030269&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/6202","name":"http://www.securityfocus.com/bid/6202","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"iPlanet Admin Server Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt","name":"http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1315","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1315","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"iplanet","cpe5":"iplanet_web_server","cpe6":"4.1_sp9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:19:28.549Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"49475","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-49475-1"},{"name":"iplanet-admin-log-xss(10692)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10692.php"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt"},{"name":"6202","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6202"},{"name":"20021118 iPlanet WebServer, remote root compromise","tags":["mailing-list","x_refsource_VULNWATCH","x_transferred"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html"},{"name":"20021119 iPlanet WebServer, remote root compromise","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=103772308030269&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-11-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"49475","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-49475-1"},{"name":"iplanet-admin-log-xss(10692)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10692.php"},{"tags":["x_refsource_MISC"],"url":"http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt"},{"name":"6202","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6202"},{"name":"20021118 iPlanet WebServer, remote root compromise","tags":["mailing-list","x_refsource_VULNWATCH"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html"},{"name":"20021119 iPlanet WebServer, remote root compromise","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=103772308030269&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1315","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"49475","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-49475-1"},{"name":"iplanet-admin-log-xss(10692)","refsource":"XF","url":"http://www.iss.net/security_center/static/10692.php"},{"name":"http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt","refsource":"MISC","url":"http://www.ngsec.com/docs/advisories/NGSEC-2002-4.txt"},{"name":"6202","refsource":"BID","url":"http://www.securityfocus.com/bid/6202"},{"name":"20021118 iPlanet WebServer, remote root compromise","refsource":"VULNWATCH","url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html"},{"name":"20021119 iPlanet WebServer, remote root compromise","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=103772308030269&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1315","datePublished":"2002-11-21T05:00:00.000Z","dateReserved":"2002-11-20T00:00:00.000Z","dateUpdated":"2024-08-08T03:19:28.549Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-11-29 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1:*:*:*:*:*:*:*","matchCriteriaId":"B2091816-7705-462D-BB91-76D07B9A1F3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp1:*:*:*:*:*:*:*","matchCriteriaId":"11794060-A796-4262-BFF5-E17388DD18FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp2:*:*:*:*:*:*:*","matchCriteriaId":"5BA1EF56-6656-44C5-9B59-0EDB84FF44A8"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp3:*:*:*:*:*:*:*","matchCriteriaId":"83651DFD-50C1-451F-AAB1-F1392790CD09"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp4:*:*:*:*:*:*:*","matchCriteriaId":"3A6338DC-E60A-4BA9-8CB3-9BA8DB6D9834"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp5:*:*:*:*:*:*:*","matchCriteriaId":"8099D845-6335-4B52-B8FB-210EB1CA7B0F"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp6:*:*:*:*:*:*:*","matchCriteriaId":"243B2B9A-920C-4EE8-A8BD-46810C6C76D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp7:*:*:*:*:*:*:*","matchCriteriaId":"B9ECA407-AA77-4155-A746-10C3F49519FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp8:*:*:*:*:*:*:*","matchCriteriaId":"667ED9E1-60A5-4338-822C-DC12965D2A46"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp9:*:*:*:*:*:*:*","matchCriteriaId":"CB2D89D1-D6AD-44BA-BEFC-50F7CB38CA36"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp10:*:*:*:*:*:*:*","matchCriteriaId":"DECE2CAC-D33D-458A-9B44-44063B0BF22B"},{"vulnerable":true,"criteria":"cpe:2.3:a:iplanet:iplanet_web_server:4.1_sp11:*:*:*:*:*:*:*","matchCriteriaId":"76C88C5B-F7D5-40A5-983D-6C757798EB81"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1315","Ordinal":"1","Title":"CVE-2002-1315","CVE":"CVE-2002-1315","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1315","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).","Type":"Description","Title":"CVE-2002-1315"},{"CveYear":"2002","CveId":"1315","Ordinal":"2","NoteData":"2002-11-21","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1315","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}