Vulnerability Name: | CVE-2005-2175 (CCN-40640) | ||||||||
Assigned: | 2005-06-06 | ||||||||
Published: | 2005-06-06 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:U/RC:UR)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:N/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: BUGTRAQ Type: Vendor Advisory 20050706 Cross site scripting in Lotus Notes web mail Source: CCN Type: BugTraq Mailing List, Wed Jul 06 2005 - 09:05:46 CDT Cross site scripting in Lotus Notes web mail Source: MITRE Type: CNA CVE-2005-2175 Source: CCN Type: SECTRACK ID: 1014440 Lotus Notes HTML Attachment Processing Lets Remote Users Conduct Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1014440 Source: CCN Type: IBM Web site Lotus Notes Source: CCN Type: OSVDB ID: 17884 IBM Lotus Notes Web Mail Attachment HTML Injection Source: XF Type: UNKNOWN lotus-notes-attachment-xss(40640) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |