[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-0663Date: (C)2006-02-13   (M)2023-12-22


Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1015610
SECUNIA-16340
BID-16577
OSVDB-23077
OSVDB-23078
OSVDB-23079
ADV-2006-0499
domino-webaccess-attachment-xss(24611)
domino-webaccess-filename-xss(24614)
domino-webaccess-javascript-xss(24613)
http://secunia.com/secunia_research/2005-38/advisory/
http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229919

CPE    2
cpe:/a:ibm:lotus_domino_inotes_client:7.0
cpe:/a:ibm:lotus_domino_inotes_client:6.5.4
CWE    1
CWE-79

© SecPod Technologies