[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254202

 
 

909

 
 

198060

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-2428Date: (C)2005-08-03   (M)2023-12-22


Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1014584
BID-14389
SECUNIA-16231
OSVDB-18462
http://marc.info/?l=bugtraq&m=112240869130356&w=2
EXPLOIT-DB-39495
http://www-1.ibm.com/support/docview.wss?uid=swg21212934
http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf
http://www.securiteam.com/securitynews/5FP0E15GLQ.html
lotus-domino-names-obtain-information(21556)

CPE    3
cpe:/a:ibm:lotus_domino:5.0
cpe:/a:ibm:lotus_domino:6.0
cpe:/a:ibm:lotus_domino:6.5

© SecPod Technologies