Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2001-1567 | First vendor Publication | 2001-12-31 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1567 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : Authentication bypassing in Lotus Domino File : nvt/domino_authentication_bypass.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
780 | IBM Lotus Domino Crafted .nsf Request Authentication Bypass Lotus Domino HTTP Service contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a request for a protected datbase us submitted via HTTP with a malformed URL. This flaw may lead to a loss of confidentiality. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Domino mab.nsf access RuleID : 1575-community - Revision : 16 - Type : SERVER-WEBAPP |
2014-01-10 | Domino mab.nsf access RuleID : 1575 - Revision : 16 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2002-05-12 | Name : A web application on the remote host has an authentication bypass vulnerability. File : domino_authentication_bypass.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:24:03 |
|
2024-11-28 12:04:54 |
|
2021-05-05 01:01:15 |
|
2021-05-04 12:01:35 |
|
2021-04-22 01:01:43 |
|
2020-05-23 01:35:44 |
|
2020-05-23 00:14:52 |
|
2016-10-18 12:00:58 |
|
2016-04-26 12:04:38 |
|
2014-02-17 10:24:21 |
|
2014-01-19 21:21:35 |
|
2013-05-11 12:07:46 |
|