
CVE-2003-1586
https://notcve.org/view.php?id=CVE-2003-1586
05 Feb 2010 — Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header. Vulnerabilidad de ejecución de comandos en sitios cruzados(XSS)en WebExpert permite a atacantes remotos inyectar código web o HTML de su elección a través de cabeceras User-Agent HTTP manipuladas. • http://www.securityfocus.com/archive/1/313867 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2003-1587
https://notcve.org/view.php?id=CVE-2003-1587
05 Feb 2010 — Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header. Vulnerabilidad de ejecución de comandos en sitios cruzados(XSS)en LoganPro permite a atacantes remotos inyectar código web o HTML de su elección a través de una cabecera User-Agent HTTP manipulada. • http://www.securityfocus.com/archive/1/313867 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2002-1654
https://notcve.org/view.php?id=CVE-2002-1654
31 Dec 2002 — iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection. • http://lists.virus.org/vulnwatch-0201/msg00008.html •

CVE-2002-1655
https://notcve.org/view.php?id=CVE-2002-1655
31 Dec 2002 — The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request. • http://cert.uni-stuttgart.de/archive/vulnwatch/2002/01/msg00007.html •

CVE-2002-1315
https://notcve.org/view.php?id=CVE-2002-1315
21 Nov 2002 — Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316). Vulnerabilidad de scripting en sitios cruzados (XSS) en el Servidor de Administración de iPlanet WebServer 4.x, hasta SP11, permite a usuarios remotos ejecutar scr... • http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html •

CVE-2002-1316
https://notcve.org/view.php?id=CVE-2002-1316
21 Nov 2002 — importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315). importInfo en el Servidor de Administración de iPlanet WebServer 4.x hasta SP11, permite al adminstrador del web ejecutar comandos arbitrarios mediante metacaractéres de shell en el parámetro dir, y posiblemente permita a ataca... • http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0078.html •

CVE-2002-0845
https://notcve.org/view.php?id=CVE-2002-0845
12 Aug 2002 — Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding. • http://marc.info/?l=bugtraq&m=102890933623192&w=2 •

CVE-2002-0686
https://notcve.org/view.php?id=CVE-2002-0686
15 Jul 2002 — Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter. Desbordamiento de búfer en la búsqueda de componentes para iPlanet Web Server (iWS) 4.1 y 6.0 permite a atacantes remotos la ejecución arbitraria de código mediante un argumento largo en el parámetro NS-rel-doc-name. • http://marc.info/?l=bugtraq&m=102622220416889&w=2 •

CVE-2001-0746 – iPlanet 4.1 Web Publisher - Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-0746
12 Oct 2001 — Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods. • https://www.exploit-db.com/exploits/20852 •

CVE-2001-0747
https://notcve.org/view.php?id=CVE-2001-0747
12 Oct 2001 — Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long method name in an HTTP request. • http://archives.neohapsis.com/archives/bugtraq/2001-05/0203.html •