IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability
BID:14164
Info
IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability
| Bugtraq ID: | 14164 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2005 12:00AM |
| Updated: | Jul 06 2005 12:00AM |
| Credit: | Discovery of this issue is credited to [email protected]. |
| Vulnerable: |
IBM Lotus Domino Enterprise Server 6.5.4 IBM Lotus Domino Enterprise Server 6.0.5 IBM Lotus Domino Enterprise Server 5.0.13 IBM Lotus Domino 6.5.4 IBM Lotus Domino 6.0.5 IBM Lotus Domino 5.0.13 |
| Not Vulnerable: | |
Discussion
IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability
IBM Lotus Notes email client is prone to an input validation vulnerability. Reports indicate that HTML and JavaScript attached to received email messages is executed automatically when the email message is viewed. Specifically, users accessing standard Notes mail templates through a Web mail client are affected.
This vulnerability may be leveraged by a remote attacker to automatically execute arbitrary script code in the context of a target user.
IBM Lotus Notes email client is prone to an input validation vulnerability. Reports indicate that HTML and JavaScript attached to received email messages is executed automatically when the email message is viewed. Specifically, users accessing standard Notes mail templates through a Web mail client are affected.
This vulnerability may be leveraged by a remote attacker to automatically execute arbitrary script code in the context of a target user.
Exploit / POC
IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability
No exploit is required, the following proof of concept email message is available:
No exploit is required, the following proof of concept email message is available:
Solution / Fix
IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability
Solution:
IBM has released an advisory to address this issue. IBM recommends that affected users should switch to IBM Domino Web Access (iNotes) introduced in Domino 5.0.8 as their Web mail interface. Domino Web Access mail template prompts the user when an attachment is clicked. Users are advised to upgrade their mail template. More details are provided in the referenced IBM advisory.
Solution:
IBM has released an advisory to address this issue. IBM recommends that affected users should switch to IBM Domino Web Access (iNotes) introduced in Domino 5.0.8 as their Web mail interface. Domino Web Access mail template prompts the user when an attachment is clicked. Users are advised to upgrade their mail template. More details are provided in the referenced IBM advisory.
References
IBM Lotus Domino Notes Mail Template Automatic Script Execution Vulnerability
References:
References: