PT-2005-3340 · Ibm · Lotus Domino

Leandro Meiners

·

Publicado

2005-08-03

·

Atualizado

2017-09-10

·

CVE-2005-2428

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lotus Domino versions R5 and R6
Description The issue allows remote attackers to obtain sensitive information by reading the HTML source. This includes the password hash in the HTTPPassword field, the password change date in the HTTPPasswordChangeDate field, the client platform in the ClntPltfrm field, the client machine name in the ClntMachine field, and the client Lotus Domino release in the ClntBld field. This occurs when "Generate HTML for all fields" is enabled in Lotus Domino R5 and R6 WebMail.
Recommendations For Lotus Domino versions R5 and R6, disable the "Generate HTML for all fields" option to prevent sensitive data from being stored in hidden form fields.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2428

Produtos afetados

Lotus Domino