Page 3 of 39 results (0.006 seconds)

CVSS: 7.8EPSS: 2%CPEs: 18EXPL: 0

31 Dec 2005 — The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference. • http://securitytracker.com/id?1015611 •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 2

21 Sep 2005 — Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters. • http://secunia.com/advisories/16830 •

CVSS: 7.5EPSS: 6%CPEs: 3EXPL: 3

03 Aug 2005 — Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a... • https://www.exploit-db.com/exploits/3302 •

CVSS: 7.5EPSS: 1%CPEs: 9EXPL: 0

03 May 2005 — Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC). • http://secunia.com/advisories/14879 •

CVSS: 6.1EPSS: 2%CPEs: 1EXPL: 2

31 Dec 2004 — Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console. • https://www.exploit-db.com/exploits/23837 •

CVSS: 3.6EPSS: 0%CPEs: 1EXPL: 3

31 Dec 2004 — Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog. • https://www.exploit-db.com/exploits/23836 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 2

31 Dec 2004 — Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command. • http://members.lycos.co.uk/r34ct/main/ibm_lotus_domino/lotus.txt •

CVSS: 6.8EPSS: 0%CPEs: 2EXPL: 0

31 Dec 2004 — Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. • http://secunia.com/advisories/11925 •

CVSS: 6.1EPSS: 1%CPEs: 8EXPL: 5

18 Oct 2004 — NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly han... • https://www.exploit-db.com/exploits/24690 •

CVSS: 7.5EPSS: 4%CPEs: 1EXPL: 2

13 Jul 2004 — Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment. • https://www.exploit-db.com/exploits/24243 •