Vulnerabilities > IBM > Lotus Quickr

DATE CVE VULNERABILITY TITLE RISK
2010-02-26 CVE-2010-0715 Remote Security vulnerability in Websphere Portal
Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the query string.
network
ibm
6.8
2010-02-26 CVE-2010-0714 Cross-Site Scripting vulnerability in IBM products
Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to inject arbitrary web script or HTML via the query string.
network
ibm CWE-79
4.3
2009-09-29 CVE-2009-3453 Cross-Site Scripting vulnerability in IBM Lotus Quickr 8.1.0
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1.0 services for WebSphere Portal allow remote attackers to inject arbitrary web script or HTML via the filename of a .odt file in a Lotus Quickr place, related to the Library template.
network
ibm CWE-79
4.3
2008-10-09 CVE-2008-4507 Permissions, Privileges, and Access Controls vulnerability in IBM Lotus Quickr 8.1
Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author via unknown vectors.
network
low complexity
ibm CWE-264
7.5
2008-10-09 CVE-2008-4506 Permissions, Privileges, and Access Controls vulnerability in IBM Lotus Quickr 8.1
Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" via unknown vectors.
network
low complexity
ibm CWE-264
7.5
2008-10-09 CVE-2008-4505 Improper Input Validation vulnerability in IBM Lotus Quickr 8.1
Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) might allow attackers to cause a denial of service (system crash) via a "nonstandard URL argument" to the OpenDocument command.
network
low complexity
ibm CWE-20
7.8
2008-08-29 CVE-2008-3860 Cross-Site Scripting vulnerability in IBM Lotus Quickr 8.1
Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page.
network
ibm microsoft CWE-79
4.3
2008-05-13 CVE-2008-2163 Cross-Site Scripting vulnerability in IBM Lotus Quickr 8.1
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
network
ibm microsoft CWE-79
4.3
2008-02-20 CVE-2008-0834 Cross-Site Scripting vulnerability in IBM Lotus Quickr 8.0/8.0.2
Cross-site scripting (XSS) vulnerability in Lotus Quickr for i5/OS before 8.0.0.2 Hotfix 11, when anonymous access is disabled on HTTP ports, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3