MEDIUM
NOTE: this issue has been disputed by the vendor
Published Feb 20, 2005
4.3
MEDIUMCVSS 2.0
EPSS 3.08%
Description
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature
Affected products
No data.
OR
- 6.0
- 6.0.1
- 6.0.2
- 6.0.2_cf2
- 6.0.3
- 6.5.0
- 6.5.1
- 6.5.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- http://marc.info/?l=bugtraq&m=109812960023736&w=2 mailing-listx_refsource_BUGTRAQ
- http://marc.info/?l=bugtraq&m=109841682529328&w=2 mailing-listx_refsource_BUGTRAQ
- http://secunia.com/advisories/12891 third-party-advisoryx_refsource_SECUNIAExploitVendor Advisory
- http://securitytracker.com/id?1011779 vdb-entryx_refsource_SECTRACKExploitVendor Advisory
- http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21187833 x_refsource_MISCExploitVendor Advisory
- http://www.kb.cert.org/vuls/id/404382 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.securityfocus.com/bid/11458 vdb-entryx_refsource_BIDExploitVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-1615 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17758 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://marc.info/?l=bugtraq&m=109812960023736&w=2 | mailing-listx_refsource_BUGTRAQ | |
| http://marc.info/?l=bugtraq&m=109841682529328&w=2 | mailing-listx_refsource_BUGTRAQ | |
| http://secunia.com/advisories/12891 | third-party-advisoryx_refsource_SECUNIAExploitVendor Advisory | |
| http://securitytracker.com/id?1011779 | vdb-entryx_refsource_SECTRACKExploitVendor Advisory | |
| http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21187833 | x_refsource_MISCExploitVendor Advisory | |
| http://www.kb.cert.org/vuls/id/404382 | third-party-advisoryx_refsource_CERT-VNUS Government Resource | |
| http://www.securityfocus.com/bid/11458 | vdb-entryx_refsource_BIDExploitVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-1615 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17758 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2005
Updated Aug 8, 2024
Reserved Feb 20, 2005
Link CVE-2004-1621
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2004-1615 Assigner mitre
Published Feb 20, 2005
Updated Aug 8, 2024
Exploited since n/a
Link EUVD-2004-1615