Описание
Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action. NOTE: this may overlap CVE-2010-0920.
Ссылки
- Exploit
- Exploit
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:ibm:lotus_domino:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:7.0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.0.1:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00224
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
почти 4 года назад
Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action. NOTE: this may overlap CVE-2010-0920.
EPSS
Процентиль: 45%
0.00224
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79