5
CVSSv2

CVE-2005-2175

Published: 09/07/2005 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote malicious users to conduct web-based attacks and steal cookies.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm lotus notes

Exploits

source: wwwsecurityfocuscom/bid/14164/info IBM Lotus Notes email client is prone to an input validation vulnerability Reports indicate that HTML and JavaScript attached to received email messages is executed automatically when the email message is viewed Specifically, users accessing standard Notes mail templates through a Web mail clie ...