Vulnerability record · CVE-2002-1654 · published 31 December 2002
CVE-2002-1654: Iplanet web server vulnerability
Iplanet · Iplanet Web Server
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
Description
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://lists.virus.org/vulnwatch-0201/msg00008.html | ExploitPatch |
| http://securitytracker.com/id?1003157 | ExploitPatch |
| http://www.kb.cert.org/vuls/id/985347 | PatchUS Government Resource |
| http://www.kb.cert.org/vuls/id/AAMN-567NFX | |
| http://www.procheckup.com/vulnerabilities/pr0105.html | |
| http://www.securiteam.com/securitynews/5IP0G0060Q.html | ExploitPatch |
| http://www.securityfocus.com/bid/3831 | ExploitPatch |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/7845 | |
| http://lists.virus.org/vulnwatch-0201/msg00008.html | ExploitPatch |
| http://securitytracker.com/id?1003157 | ExploitPatch |
| http://www.kb.cert.org/vuls/id/985347 | PatchUS Government Resource |
| http://www.kb.cert.org/vuls/id/AAMN-567NFX | |
| http://www.procheckup.com/vulnerabilities/pr0105.html | |
| http://www.securiteam.com/securitynews/5IP0G0060Q.html | ExploitPatch |
| http://www.securityfocus.com/bid/3831 | ExploitPatch |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/7845 |
Track CVE-2002-1654 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1654), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.