CVE-2020-9314
Oracle iplanet_web_server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2020-9314 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.
Description
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 11, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
iplanet_web_serverBrowse Oracle / iplanet_web_server | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMOracle iPlanet Web Server 7.0.x - Image InjectionCVSS 4.8
Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516.
Impact
Attackers can inject malicious images into the admin console, potentially leading to social engineering, phishing attacks, or interface manipulation.
Remediation
Oracle iPlanet Web Server 7.0.x is no longer supported. Migrate to a supported platform or restrict network access to the administration console.
Source: ProjectDiscovery