IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability

BID:14164

Info

IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability

Bugtraq ID: 14164
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Jul 06 2005 12:00AM
Updated: Jul 06 2005 12:00AM
Credit: Discovery of this issue is credited to [email protected].
Vulnerable: IBM Lotus Domino Enterprise Server 6.5.4
IBM Lotus Domino Enterprise Server 6.0.5
IBM Lotus Domino Enterprise Server 5.0.13
IBM Lotus Domino 6.5.4
IBM Lotus Domino 6.0.5
IBM Lotus Domino 5.0.13
Not Vulnerable:

Discussion

IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability

IBM Lotus Notes email client is prone to an input validation vulnerability. Reports indicate that HTML and JavaScript attached to received email messages is executed automatically when the email message is viewed. Specifically, users accessing standard Notes mail templates through a Web mail client are affected.

This vulnerability may be leveraged by a remote attacker to automatically execute arbitrary script code in the context of a target user.

Exploit / POC

IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability

No exploit is required, the following proof of concept email message is available:

Solution / Fix

IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability

Solution:
IBM has released an advisory to address this issue. IBM recommends that affected users should switch to IBM Domino Web Access (iNotes) introduced in Domino 5.0.8 as their Web mail interface. Domino Web Access mail template prompts the user when an attachment is clicked. Users are advised to upgrade their mail template. More details are provided in the referenced IBM advisory.

References

IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report