Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516.
id: CVE-2020-9314
info:
name: Oracle iPlanet Web Server 7.0.x - Image Injection
author: Dhiyane
...