This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ibm First view 2010-01-09
Product Lotus Inotes Last view 2016-11-24
Version 8.5.3.3 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:ibm:lotus_inotes

Activity : Overall

Related : CVE

  Date Alert Description
5.4 2016-11-24 CVE-2016-0282

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYHAAHNUS.

2.6 2013-12-21 CVE-2013-4065

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPR TCLE98ZKRP.

2.1 2013-12-21 CVE-2013-4064

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9ARMFA.

4.3 2013-12-21 CVE-2013-4063

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP.

6.8 2010-03-03 CVE-2010-0921

Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to hijack the authentication of unspecified victims via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."

4.3 2010-03-03 CVE-2010-0920

Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."

10 2010-03-03 CVE-2010-0918

Multiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 have unknown impact and attack vectors.

10 2010-01-09 CVE-2010-0275

Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58.

10 2010-01-09 CVE-2010-0274

Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5.

10 2010-01-09 CVE-2009-4594

Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, aka SPR SDOY7RHBNH.

CWE : Common Weakness Enumeration

%idName
83% (5) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
16% (1) CWE-352 Cross-Site Request Forgery (CSRF)

Open Source Vulnerability Database (OSVDB)

id Description
62755 IBM Lotus iNotes UltraLite Functionality Multiple Unspecified Issues
62754 IBM Lotus iNotes Get Filter and Referer Check Fixes Weakness XSS
62753 IBM Lotus iNotes Get Filter and Referer Check Fixes Weakness CSRF
61646 IBM Lotus Domino iNotes Ultra-light Mode Status-alerts URL Command Handling W...
61645 IBM Lotus Domino iNotes Ultra-light Mode Edit Contact Scene Unspecified Issue...
61637 IBM Lotus Domino iNotes Unspecified Issue (SPR SDOY7RHBNH)

Nessus® Vulnerability Scanner

id Description
2016-12-15 Name: A business collaboration application running on the remote host is affected b...
File: domino_swg21992835.nasl - Type: ACT_GATHER_INFO
2014-01-08 Name: The remote server is affected by multiple cross-site scripting vulnerabilities.
File: domino_8_5_3fp6.nasl - Type: ACT_GATHER_INFO
2014-01-08 Name: The remote server is affected by multiple vulnerabilities.
File: domino_9_0_1.nasl - Type: ACT_GATHER_INFO
2014-01-08 Name: The remote host has software installed that is affected by multiple cross-sit...
File: lotus_domino_8_5_3_fp6.nasl - Type: ACT_GATHER_INFO
2014-01-08 Name: The remote host has software installed that is affected by multiple vulnerabi...
File: lotus_domino_9_0_1.nasl - Type: ACT_GATHER_INFO