Back

CVE-2002-1315

Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).

Published: Nov 29, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (12)

Vendor Product Version
iplanet iplanet_web_server 4.1
iplanet iplanet_web_server 4.1_sp1
iplanet iplanet_web_server 4.1_sp2
iplanet iplanet_web_server 4.1_sp3
iplanet iplanet_web_server 4.1_sp4
iplanet iplanet_web_server 4.1_sp5
iplanet iplanet_web_server 4.1_sp6
iplanet iplanet_web_server 4.1_sp7
iplanet iplanet_web_server 4.1_sp8
iplanet iplanet_web_server 4.1_sp9
iplanet iplanet_web_server 4.1_sp10
iplanet iplanet_web_server 4.1_sp11

GitHub Security Advisory GHSA-6j9f-c956-rhqf

Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 1.64%

Top 26% most likely to be exploited

Threat Score 27.7 / 100

Data Sources

NVD EPSS GitHub