Showing 1 vulnerability on this page for iplanet_web_server

Signals CISA KEV Ransomware Nuclei
Oracle vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Oracle iplanet_web_server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

CWE-74CWE-79May 10, 20201 related artifact
CVSS4.8v3.1EPSS1.28%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX