{"api_version":"1","generated_at":"2026-07-23T06:09:01+00:00","cve":"CVE-2005-2428","urls":{"html":"https://cve.report/CVE-2005-2428","api":"https://cve.report/api/cve/CVE-2005-2428.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2428","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2428"},"summary":{"title":"CVE-2005-2428","description":"Lotus Domino R5 and R6 WebMail, with \"Generate HTML for all fields\" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-08-03 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/39495/","name":"https://www.exploit-db.com/exploits/39495/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Lotus Domino R8 - Password Hash Extraction - Windows webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14389","name":"http://www.securityfocus.com/bid/14389","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Lotus Domino Password Encryption Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/18462","name":"http://www.osvdb.org/18462","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securiteam.com/securitynews/5FP0E15GLQ.html","name":"http://www.securiteam.com/securitynews/5FP0E15GLQ.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecuriTeam.com ™ - Default Configuration Information Disclosure in Lotus Domino (Including Password Hashes)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112240869130356&w=2","name":"http://marc.info/?l=bugtraq&m=112240869130356&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'CYBSEC - Security Advisory: Default Configuration Information' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16231/","name":"http://secunia.com/advisories/16231/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Lotus Domino Webmail Information Disclosure Security Issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf","name":"http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21556","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21556","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1014584","name":"http://securitytracker.com/id?1014584","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - IBM Lotus Domino Discloses Hashed Passwords and Other Information to Remote Authenticated Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21212934","name":"http://www-1.ibm.com/support/docview.wss?uid=swg21212934","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2428","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2428","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2428","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_domino","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2428","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_domino","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2428","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_domino","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:29:59.319Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20050726 CYBSEC - Security Advisory: Default Configuration Information","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112240869130356&w=2"},{"name":"14389","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14389"},{"name":"39495","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/39495/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21212934"},{"name":"1014584","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014584"},{"name":"18462","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/18462"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securiteam.com/securitynews/5FP0E15GLQ.html"},{"name":"16231","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16231/"},{"name":"lotus-domino-names-obtain-information(21556)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21556"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Lotus Domino R5 and R6 WebMail, with \"Generate HTML for all fields\" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-09T09:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20050726 CYBSEC - Security Advisory: Default Configuration Information","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112240869130356&w=2"},{"name":"14389","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14389"},{"name":"39495","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/39495/"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21212934"},{"name":"1014584","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014584"},{"name":"18462","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/18462"},{"tags":["x_refsource_MISC"],"url":"http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf"},{"tags":["x_refsource_MISC"],"url":"http://www.securiteam.com/securitynews/5FP0E15GLQ.html"},{"name":"16231","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16231/"},{"name":"lotus-domino-names-obtain-information(21556)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21556"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2428","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Lotus Domino R5 and R6 WebMail, with \"Generate HTML for all fields\" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20050726 CYBSEC - Security Advisory: Default Configuration Information","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112240869130356&w=2"},{"name":"14389","refsource":"BID","url":"http://www.securityfocus.com/bid/14389"},{"name":"39495","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/39495/"},{"name":"http://www-1.ibm.com/support/docview.wss?uid=swg21212934","refsource":"CONFIRM","url":"http://www-1.ibm.com/support/docview.wss?uid=swg21212934"},{"name":"1014584","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014584"},{"name":"18462","refsource":"OSVDB","url":"http://www.osvdb.org/18462"},{"name":"http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf","refsource":"MISC","url":"http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf"},{"name":"http://www.securiteam.com/securitynews/5FP0E15GLQ.html","refsource":"MISC","url":"http://www.securiteam.com/securitynews/5FP0E15GLQ.html"},{"name":"16231","refsource":"SECUNIA","url":"http://secunia.com/advisories/16231/"},{"name":"lotus-domino-names-obtain-information(21556)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21556"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2428","datePublished":"2005-08-03T04:00:00.000Z","dateReserved":"2005-08-03T00:00:00.000Z","dateUpdated":"2024-08-07T22:29:59.319Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-08-03 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_domino:5.0:*:*:*:*:*:*:*","matchCriteriaId":"3264F8E8-C40A-4C5C-BF2C-BD4690FE7EC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_domino:6.0:*:*:*:*:*:*:*","matchCriteriaId":"A9989FEB-3B5E-40FF-BDBF-CFC835BCF93B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_domino:6.5:*:*:*:*:*:*:*","matchCriteriaId":"53D6F4E6-2C8A-40B6-9DB9-38E15D2AFEEF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2428","Ordinal":"1","Title":"CVE-2005-2428","CVE":"CVE-2005-2428","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2428","Ordinal":"1","NoteData":"Lotus Domino R5 and R6 WebMail, with \"Generate HTML for all fields\" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.","Type":"Description","Title":"CVE-2005-2428"},{"CveYear":"2005","CveId":"2428","Ordinal":"2","NoteData":"2005-08-03","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2428","Ordinal":"3","NoteData":"2017-09-09","Type":"Other","Title":"Modified"}]}}}