Files
CVEs-PoC/2020/CVE-2020-9314.md
T
2025-09-29 21:09:30 +02:00

847 B

CVE-2020-9314

Description

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

POC

Reference

Github

No PoCs found on GitHub currently.