10
CVSSv2

CVE-2011-1519

Published: 25/03/2011 Updated: 09/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote malicious users to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm lotus domino 7.0.2.3

ibm lotus domino 7.0.3.1

ibm lotus domino 7.0.4.1

ibm lotus domino 7.0.4.2

ibm lotus domino 7.0.1.1

ibm lotus domino 7.0.2

ibm lotus domino 7.0.1

ibm lotus domino 7.0.2.1

ibm lotus domino 7.0

ibm lotus domino 7.0.2.2

ibm lotus domino 7.0.3

ibm lotus domino 7.0.4

ibm lotus domino 8.5.1.3

ibm lotus domino 8.0.1

ibm lotus domino 8.5.1

ibm lotus domino 8.5.2

ibm lotus domino 8.5.3

ibm lotus domino 8.0.2

ibm lotus domino 8.0.2.6

ibm lotus domino 8.0.2.3

ibm lotus domino 8.5.1.4

ibm lotus domino 8.5.1.1

ibm lotus domino 8.0

ibm lotus domino 8.5.1.2

ibm lotus domino 8.5.1.5

ibm lotus domino 8.5.0.1

ibm lotus domino 8.5.2.2

ibm lotus domino 8.0.2.4

ibm lotus domino 8.0.2.1

ibm lotus domino 8.0.2.5

ibm lotus domino 8.5.2.1

ibm lotus domino 8.5.0

ibm lotus domino 8.0.2.2

Exploits

# Exploit Title: IBM Lotus Domino Controller auth bypass # Date:30/11/2011 # Author: Alexey Sintsov # Software Link: wwwibmcom/ # Version:853/852 FP3 (0day)  # Tested on: Windows 7 / Windows 2008 # CVE : CVE-2011-1519 Application: IBM Lotus Domino Controller Versions Affected: <=852 FP3, <=853 Manager 40 prior to Update ...
IBM Lotus Domino versions 853 and 852 FP3 suffer from an authentication bypass vulnerability ...