4
CVSSv2

CVE-2006-1948

Published: 20/04/2006 Updated: 05/09/2008
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 prior to 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote malicious users to trick a user into sending e-mail to an unauthorized recipient.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm lotus notes 6.0

ibm lotus notes 6.5