Injection Vulnerability in Sun ONE Web Server Log Files Allows Remote Attacks
CVE-2003-1577
Currently unrated
Summary
The Sun ONE Web Server versions 4.1 SP12 and 6.0 SP5, when DNS resolution is utilized for identifying client IP addresses, is susceptible to an injection flaw. Attackers can exploit this vulnerability to insert arbitrary text into the server's log files. This opens avenues for cross-site scripting (XSS) attacks by manipulating HTTP requests alongside crafted DNS responses, which may compromise web applications using the iPlanet Log Analyzer. The issue is characterized as an 'Inverse Lookup Log Corruption (ILLC)', differentiating it from related vulnerabilities, CVE-2002-1315 and CVE-2002-1316.
References
Timeline
Vulnerability published
Vulnerability Reserved