| Vulnerability Name: | CVE-2007-5924 (CCN-38585) | ||||||||
| Assigned: | 2007-11-07 | ||||||||
| Published: | 2007-11-07 | ||||||||
| Updated: | 2011-03-08 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-79 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2007-5924 Source: CCN Type: JVN#84565055 Lotus Domino XSS Source: JVN Type: UNKNOWN JVN#84565055 Source: OSVDB Type: UNKNOWN 39720 Source: CCN Type: SA27509 IBM Lotus Domino Web Server Cross-Site Scripting Vulnerability Source: SECUNIA Type: UNKNOWN 27509 Source: CCN Type: IBM Technote (FAQ) 1263871 Cross-site scripting (XSS) vulnerability in IBM Lotus Domino Web server Source: CONFIRM Type: UNKNOWN http://www-1.ibm.com/support/docview.wss?uid=swg21263871 Source: CONFIRM Type: UNKNOWN http://www-1.ibm.com/support/docview.wss?uid=swg27010980 Source: CCN Type: OSVDB ID: 39720 IBM Lotus Domino Web Server Unspecified XSS Source: CCN Type: BID-26298 IBM Lotus Domino Web Server Unspecified Cross-Site Scripting Security Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-3700 Source: XF Type: UNKNOWN domino-webserver-xss(38585) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||