Vulnerability Name: | CCN-4506 | ||||||
Published: | 2000-05-19 | ||||||
Updated: | 2000-05-19 | ||||||
Summary: | Lotus Domino Server could allow files to be modified by unauthorized users if the files are not properly configured to restrict access. If certain files have improperly configured access control lists (ACLs), a remote attacker can modify the files through a Web browser. By sending a URL to the server containing ?EditDocument, an attacker can modify the requested document through the browser. If administrator has set up ACLs correctly this is not a problem. | ||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||
CVSS v2 Severity: | 6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P)
| ||||||
Vulnerability Consequences: | File Manipulation | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri May 19 2000 - 21:01:13 CDT Black Watch Labs Vulnerability Alert Source: XF Type: UNKNOWN domino-doc-modify(4506) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |