4.3
CVSSv2

CVE-2006-0663

Published: 13/02/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote malicious users to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java
script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm lotus domino inotes client 6.5.4

ibm lotus domino inotes client 7.0

Exploits

source: wwwsecurityfocuscom/bid/16577/info IBM Lotus Domino iNotes is prone to multiple HTML- and script-injection vulnerabilities These vulnerabilities can allow attackers to carry out a variety of attacks, including theft of cookie-based authentication credentials A proof of concept example for the issue exploited through a 'javasc ...
source: wwwsecurityfocuscom/bid/16577/info IBM Lotus Domino iNotes is prone to multiple HTML- and script-injection vulnerabilities These vulnerabilities can allow attackers to carry out a variety of attacks, including theft of cookie-based authentication credentials Proof of concept for the email subject field script injection: &l ...