Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2004-2763
Disclosure Date: June 01, 2009 (last updated October 04, 2023)
The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
0
Attacker Value
Unknown
CVE-2007-0183
Disclosure Date: January 12, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2002-1655
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request.
0
Attacker Value
Unknown
CVE-2002-1654
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
0
Attacker Value
Unknown
CVE-2002-1315
Disclosure Date: November 29, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).
0
Attacker Value
Unknown
CVE-2002-1316
Disclosure Date: November 29, 2002 (last updated February 22, 2025)
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).
0
Attacker Value
Unknown
CVE-2002-1042
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.
0
Attacker Value
Unknown
CVE-2002-0845
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding.
0
Attacker Value
Unknown
CVE-2002-0686
Disclosure Date: July 23, 2002 (last updated February 22, 2025)
Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter.
0
Attacker Value
Unknown
CVE-2001-0746
Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.
0