Lotus Domino Internal IP address Disclosure Vulnerability
BID:3350
Info
Lotus Domino Internal IP address Disclosure Vulnerability
| Bugtraq ID: | 3350 |
| Class: | Design Error |
| CVE: |
CVE-2001-1018 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered and posted to Bugtraq by [email protected] on Sep 19, 2001. |
| Vulnerable: |
Lotus Domino 5.0.8 |
| Not Vulnerable: | |
Discussion
Lotus Domino Internal IP address Disclosure Vulnerability
A vulnerability has been discovered in Lotus Domino server that may result in the disclosure of the server's internal address.
If a specially formed GET request, a path segment comprised of numerous '/' characters, is submitted to a target Domino server. Lotus Domino will reveal the internal IP address of the server.
Further technical details are forthcoming.
A vulnerability has been discovered in Lotus Domino server that may result in the disclosure of the server's internal address.
If a specially formed GET request, a path segment comprised of numerous '/' characters, is submitted to a target Domino server. Lotus Domino will reveal the internal IP address of the server.
Further technical details are forthcoming.
Exploit / POC
Lotus Domino Internal IP address Disclosure Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Lotus Domino Internal IP address Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Lotus Domino Internal IP address Disclosure Vulnerability
References:
References: