Lotus Domino Unspecified Cross-Site Scripting Vulnerability
BID:14901
Info
Lotus Domino Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14901 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2005 12:00AM |
| Updated: | Sep 22 2005 12:00AM |
| Credit: | Announced by the vendor. |
| Vulnerable: |
IBM Lotus Domino 6.5.4 |
| Not Vulnerable: | |
Discussion
Lotus Domino Unspecified Cross-Site Scripting Vulnerability
IBM Lotus Domino is prone to a cross-site scripting vulnerability. This is due to insufficient input validation of data supplied through URI parameters.
An attacker may exploit this by enticing a victim user into visiting a malicious link that contains HTML and script code. If the link is followed, the embedded hostile HTML and script code may be interpreted by the victim's browser. The hostile code would be able to access properties of the site hosting the vulnerable software.
Exploitation may permit theft of cookie-based authentication credentials. Other attacks are also possible.
IBM Lotus Domino is prone to a cross-site scripting vulnerability. This is due to insufficient input validation of data supplied through URI parameters.
An attacker may exploit this by enticing a victim user into visiting a malicious link that contains HTML and script code. If the link is followed, the embedded hostile HTML and script code may be interpreted by the victim's browser. The hostile code would be able to access properties of the site hosting the vulnerable software.
Exploitation may permit theft of cookie-based authentication credentials. Other attacks are also possible.
Exploit / POC
Lotus Domino Unspecified Cross-Site Scripting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Lotus Domino Unspecified Cross-Site Scripting Vulnerability
Solution:
This issue has been addressed in Lotus Domino 6.5.4 FP1 and Domino 7.0. Please see the References section for details on obtaining fixes from IBM.
Solution:
This issue has been addressed in Lotus Domino 6.5.4 FP1 and Domino 7.0. Please see the References section for details on obtaining fixes from IBM.
References
Lotus Domino Unspecified Cross-Site Scripting Vulnerability
References:
References: