CVE-2005-2428
Summary
| CVE | CVE-2005-2428 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-08-03 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Lotus Domino | 5.0 | All | All | All |
| Application | Ibm | Lotus Domino | 6.0 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Lotus Domino R8 - Password Hash Extraction - Windows webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| IBM Lotus Domino Password Encryption Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/18462 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecuriTeam.com ™ - Default Configuration Information Disclosure in Lotus Domino (Including Password Hashes) | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | |
| 'CYBSEC - Security Advisory: Default Configuration Information' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Secunia - Advisories - Lotus Domino Webmail Information Disclosure Security Issue | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domin... | af854a3a-2127-422b-91ae-364da2661108 | www.cybsec.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - IBM Lotus Domino Discloses Hashed Passwords and Other Information to Remote Authenticated Users | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.