← Vulnerability feed

Vulnerability record · CVE-2002-1316 · published 29 November 2002

CVE-2002-1316: Iplanet web server vulnerability

Iplanet · Iplanet Web Server

importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).

6.8 CVSS 2.0 Medium EPSS 2.0% · top 19.7%
6.8CVSS 2.0 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1316 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2001-0746Iplanet web server vulnerabilityBuffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and po…EPSS 15%10.0CVE-2001-0431Iplanet web server vulnerabilityVulnerability in iPlanet Web Server Enterprise Edition 4.x.EPSS 1.5%10.0CVE-2000-1077Iplanet web server vulnerabilityBuffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filenam…EPSS 3.1%7.5CVE-2002-1654Iplanet web server vulnerabilityiPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the…EPSS 2.6%7.5CVE-2002-0845Iplanet web server vulnerabilityBuffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked trans…EPSS 13%7.5CVE-2002-0686Iplanet web server vulnerabilityBuffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code…EPSS 4.3%7.5CVE-2001-0747Iplanet web server vulnerabilityBuffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of service a…EPSS 2.6%6.8CVE-2002-1315Iplanet web server vulnerabilityCross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2002-1316), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.