PT-2008-2809 · Ibm · Ibm Lotus Quickr+1
Published
2008-03-09
·
Updated
2018-10-11
·
CVE-2008-1216
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Lotus Quickr version 8.0
IBM Lotus QuickPlace versions 7.x
Description
The issue allows remote attackers to inject arbitrary web script or HTML via a Calendar OpenDocument action to "main.nsf" with a
Count parameter containing a JavaScript event in a malformed element. This can be demonstrated by an onload event in an IFRAME element.Recommendations
For IBM Lotus Quickr version 8.0, update the software to properly identify URIs containing cross-site scripting attack strings.
For IBM Lotus QuickPlace versions 7.x, restrict access to the Calendar OpenDocument action until a proper fix is applied.
As a temporary workaround, consider disabling the
onload event in IFRAME elements to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Lotus Quickplace
Ibm Lotus Quickr