Vulnerabilities > CVE-2005-3015 - Cross-Site Scripting vulnerability in IBM Lotus Domino and Lotus Domino Enterprise Server

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
ibm
nessus

Summary

Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.

Vulnerable Configurations

Part Description Count
Application
Ibm
2

Nessus

NASL familyCGI abuses : XSS
NASL idLOTUS_DOMINO_XSS.NASL
descriptionThe remote host runs Lotus Domino web server. The installed version of Lotus Domino is vulnerable to multiple cross- site scripting attacks due to a lack of sanitization of user-supplied data. Successful exploitation of this issue may allow an attacker to execute malicious script code in a user
last seen2020-06-01
modified2020-06-02
plugin id19764
published2005-09-20
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/19764
titleLotus Domino Multiple Script Src / BaseTarget XSS