CVE-2004-1621
Summary
| CVE | CVE-2004-1621 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-10-18 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Lotus Domino | 6.0 | All | All | All |
| Application | Ibm | Lotus Domino | 6.0.1 | All | All | All |
| Application | Ibm | Lotus Domino | 6.0.2 | All | All | All |
| Application | Ibm | Lotus Domino | 6.0.2_cf2 | All | All | All |
| Application | Ibm | Lotus Domino | 6.0.3 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.0 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.1 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ]' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityTracker.com Archives - Lotus Notes/Domino Square Bracket Encoding Failure Lets Remote Users Conduct Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Exploit, Vendor Advisory |
| IBM Lotus Domino Cross-Site Scripting and HTML Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| 'IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] )' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CERT Vulnerability Notes Database | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Secunia - Advisories - IBM Lotus Domino Server Potential Cross-Site Scripting Security Issue | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.