Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2004-1621
Description:** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature.
Test IDs: 1.3.6.1.4.1.25623.1.0.15514  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2004-1621
BugTraq ID: 11458
http://www.securityfocus.com/bid/11458
Bugtraq: 20041018 IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) (Google Search)
http://marc.info/?l=bugtraq&m=109812960023736&w=2
Bugtraq: 20041021 Re: IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] ) (Google Search)
http://marc.info/?l=bugtraq&m=109841682529328&w=2
CERT/CC vulnerability note: VU#404382
http://www.kb.cert.org/vuls/id/404382
http://www-1.ibm.com/support/docview.wss?rs=463&uid=swg21187833
http://securitytracker.com/id?1011779
http://secunia.com/advisories/12891
XForce ISS Database: lotus-notes-xss(17758)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17758




© 1998-2025 E-Soft Inc. All rights reserved.