Vulnerability Name: | CVE-2004-1621 (CCN-17758) | ||||||||
Assigned: | 2004-10-18 | ||||||||
Published: | 2004-10-18 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | ** DISPUTED ** Note: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. Note: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Oct 18 2004 - 13:48:17 CDT IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) in computed field/text, allowing XSS Source: CCN Type: BugTraq Mailing List, Mon Oct 18 2004 - 16:31:03 CDT Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) in computed field/text, allowing XSS Source: CCN Type: BugTraq Mailing List, Thu Oct 21 2004 - 13:49:52 CDT Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) in computed field/text, allowing XSS (Risk increased) Source: MITRE Type: CNA CVE-2004-1621 Source: BUGTRAQ Type: UNKNOWN 20041018 IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) Source: BUGTRAQ Type: UNKNOWN 20041021 Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) Source: CCN Type: SA12891 IBM Lotus Domino Server Potential Cross-Site Scripting Security Issue Source: SECUNIA Type: Exploit, Vendor Advisory 12891 Source: CCN Type: SECTRACK ID: 1011779 Lotus Notes/Domino Square Bracket Encoding Failure Lets Remote Users Conduct Cross-Site Scripting Attacks Source: SECTRACK Type: Exploit, Vendor Advisory 1011779 Source: MISC Type: Exploit, Vendor Advisory http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21187833 Source: CERT-VN Type: US Government Resource VU#404382 Source: CCN Type: OSVDB ID: 10966 IBM Lotus Notes/Domino Square Brackets Encoding Failure XSS Source: BID Type: Exploit, Vendor Advisory 11458 Source: CCN Type: BID-11458 IBM Lotus Domino Cross-Site Scripting and HTML Injection Vulnerabilities Source: XF Type: UNKNOWN lotus-notes-xss(17758) Source: XF Type: UNKNOWN lotus-notes-xss(17758) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |