Vulnerabilities > CVE-2001-0327 - Unspecified vulnerability in Iplanet web Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN iplanet
nessus
Summary
iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Web Servers |
NASL id | IPLANET_DATA_SNAG.NASL |
description | According to its self reported version number, the remote iPlanet web server is affected by an information disclosure vulnerability wherein a remote user can retrieve sensitive data from memory allocation pools or cause a denial of service against the server. *** Since Nessus solely relied on the banner of this server, *** (and iPlanet 4 does not include the SP level in the banner), *** to issue this alert, this may be a false positive. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11856 |
published | 2003-09-29 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11856 |
title | iPlanet Web Server Enterprise Edition URL-encoded Host: Information Disclosure |
code |
|
References
- http://www.atstake.com/research/advisories/2001/a041601-1.txt
- http://www.atstake.com/research/advisories/2001/a041601-1.txt
- http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html
- http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html
- http://www.kb.cert.org/vuls/id/276767
- http://www.kb.cert.org/vuls/id/276767
- http://www.osvdb.org/5704
- http://www.osvdb.org/5704