Files
CVEs-PoC/2020/CVE-2020-9314.md
T
2024-06-18 02:51:15 +02:00

836 B

CVE-2020-9314

Description

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

POC

Reference

Github

No PoCs found on GitHub currently.