Back to search
CVE-2003-1578
Published: Feb 5, 2010
Modified: Aug 8, 2024
PUBLISHED
Description
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
201453
vendor-advisory
x_refsource_SUNALERT
7012
vdb-entry
x_refsource_BID
20030304 Log corruption on multiple webservers, log analyzers,...
mailing-list
x_refsource_BUGTRAQ
iplanet-logpreview-security-bypass(56633)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now