IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability
BID:36305
Info
IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability
| Bugtraq ID: | 36305 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3114 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | Marc Ruef |
| Vulnerable: |
IBM Lotus Notes 8.5 |
| Not Vulnerable: | |
Discussion
IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability
IBM Lotus Notes is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Arbitrary script code supplied by the attacker would run with elevated privileges since it is rendered within the 'Local' security zone.
Lotus Notes 8.5 is vulnerable; other versions may also be affected.
IBM Lotus Notes is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Arbitrary script code supplied by the attacker would run with elevated privileges since it is rendered within the 'Local' security zone.
Lotus Notes 8.5 is vulnerable; other versions may also be affected.
Exploit / POC
IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious RSS feed.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious RSS feed.
Solution / Fix
IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability
Solution:
Reportedly, this issue has been resolved in a hotfix. Please see the references for details.
Solution:
Reportedly, this issue has been resolved in a hotfix. Please see the references for details.
References
IBM Lotus Notes RSS Reader Widget HTML Injection Vulnerability
References:
References: