CVE-2020-9314

MEDIUM EXPLOITED NUCLEI

Oracle Iplanet Web Server < 7.0.27 - XSS

Title source: rule

Description

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

Nuclei Templates (1)

Oracle iPlanet Web Server 7.0.x - Image Injection
MEDIUMby DhiyaneshDk
Shodan: Oracle-iPlanet-Web-Server
FOFA: app="Oracle-iPlanet-Web-Server"

Scores

CVSS v3 4.8
EPSS 0.1201
EPSS Percentile 93.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

VulnCheck KEV 2026-02-11
CWE
CWE-79
Status published
Products (1)
oracle/iplanet_web_server 7.0 - 7.0.27
Published May 10, 2020
Tracked Since Feb 18, 2026