PT-2005-3340 · Ibm · Lotus Domino
Leandro Meiners
·
Published
2005-08-03
·
Updated
2017-09-10
·
CVE-2005-2428
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Lotus Domino versions R5 and R6
Description
The issue allows remote attackers to obtain sensitive information by reading the HTML source. This includes the password hash in the
HTTPPassword field, the password change date in the HTTPPasswordChangeDate field, the client platform in the ClntPltfrm field, the client machine name in the ClntMachine field, and the client Lotus Domino release in the ClntBld field. This occurs when "Generate HTML for all fields" is enabled in Lotus Domino R5 and R6 WebMail.Recommendations
For Lotus Domino versions R5 and R6, disable the "Generate HTML for all fields" option to prevent sensitive data from being stored in hidden form fields.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lotus Domino