** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-10T22:23:34

Updated: 2024-08-04T10:26:16.041Z

Reserved: 2020-02-20T00:00:00

Link: CVE-2020-9314

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-05-10T23:15:10.907

Modified: 2021-07-21T11:39:23.747

Link: CVE-2020-9314

cve-icon Redhat

No data.