CVE-2002-1654
Last modified
CVE-2002-1654 is a vulnerability of currently unknown severity. iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.. EPSS estimates a 2.62% chance of exploitation in the next 30 days.
Description
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iplanet | Iplanet Web Server | 6.0 |
| Iplanet | Iplanet Web Server | enterprise_4.0 |
| Iplanet | Iplanet Web Server | enterprise_4.1 |
| Netscape | Enterprise Server | 2.0 |
| Netscape | Enterprise Server | 3.0 |
| Netscape | Enterprise Server | 3.1 |
| Netscape | Enterprise Server | 3.2 |
| Netscape | Enterprise Server | 3.3 |
| Netscape | Enterprise Server | 3.4 |
| Netscape | Enterprise Server | 3.5 |
| Netscape | Enterprise Server | 3.6 |
References
- http://lists.virus.org/vulnwatch-0201/msg00008.htmlExploit, Patch
- http://securitytracker.com/id?1003157Exploit, Patch
- http://www.kb.cert.org/vuls/id/985347Patch, US Government Resource
- http://www.securiteam.com/securitynews/5IP0G0060Q.htmlExploit, Patch
- http://www.securityfocus.com/bid/3831Exploit, Patch
- http://lists.virus.org/vulnwatch-0201/msg00008.htmlExploit, Patch
- http://securitytracker.com/id?1003157Exploit, Patch
- http://www.kb.cert.org/vuls/id/985347Patch, US Government Resource
- http://www.securiteam.com/securitynews/5IP0G0060Q.htmlExploit, Patch
- http://www.securityfocus.com/bid/3831Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-1654?
How severe is CVE-2002-1654?
How do I fix CVE-2002-1654?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-1648Cross-site request forgery (CSRF) vulnerability in compose.p…
- CVE-2002-1649Cross-site scripting (XSS) vulnerability in read_body.php in…
- CVE-2002-1650The spell checker plugin (check_me.mod.php) for SquirrelMail…
- CVE-2002-1651Cross-site scripting (XSS) vulnerability in Verity Search97 …
- CVE-2002-1652Buffer overflow in cgicso.c for cgiemail 1.6 allows remote a…
- CVE-2002-1653Farm9 Cryptcat, when started in server mode with the -e opti…
- CVE-2002-1655The Web Publishing feature in Netscape Enterprise Server 3.x…
- CVE-2002-1656X-News (x_news) 1.1 and earlier allows attackers to authenti…
- CVE-2002-1657PostgreSQL uses the username for a salt when generating pass…7.5
- CVE-2002-1658Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may …
- CVE-2002-1659user_profile.asp in PortalApp 2.2 allows local users to gain…
- CVE-2002-1660calendar.php in vBulletin before 2.2.0 allows remote attacke…
Are you affected by CVE-2002-1654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
