CVE-2006-0663
published 2006-02-13CVE-2006-0663: Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
5.56%
91.9th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | lotus_domino_inotes_client | — | — |
| ibm | lotus_domino_inotes_client | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
IBM Lotus Domino 6.x/7.0 - iNotes JavaScript: Filter Bypass
exploitdb·2006-02-10
CVE-2006-0663 IBM Lotus Domino 6.x/7.0 - iNotes JavaScript: Filter Bypass
IBM Lotus Domino 6.x/7.0 - iNotes JavaScript: Filter Bypass
---
source: https://www.securityfocus.com/bid/16577/info
IBM Lotus Domino iNotes is prone to multiple HTML- and script-injection vulnerabilities.
These vulnerabilities can allow attackers to carry out a variety of attacks, including theft of cookie-based authentication credentials.
A proof of concept example for the issue exploited through a 'javascript:' URI is available:
Link
Exploit-DB
IBM Lotus Domino 6.x/7.0 iNotes - Email Subject Cross-Site Scripting
exploitdb·2006-02-10
CVE-2006-0663 IBM Lotus Domino 6.x/7.0 iNotes - Email Subject Cross-Site Scripting
IBM Lotus Domino 6.x/7.0 iNotes - Email Subject Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/16577/info
IBM Lotus Domino iNotes is prone to multiple HTML- and script-injection vulnerabilities.
These vulnerabilities can allow attackers to carry out a variety of attacks, including theft of cookie-based authentication credentials.
Proof of concept for the email subject field script injection:
alert("Vulnerable!");
No writeups or analysis indexed.
http://secunia.com/advisories/16340http://secunia.com/secunia_research/2005-38/advisory/http://securitytracker.com/id?1015610http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229919http://www.osvdb.org/23077http://www.osvdb.org/23078http://www.osvdb.org/23079http://www.securityfocus.com/bid/16577http://www.vupen.com/english/advisories/2006/0499https://exchange.xforce.ibmcloud.com/vulnerabilities/24611https://exchange.xforce.ibmcloud.com/vulnerabilities/24613https://exchange.xforce.ibmcloud.com/vulnerabilities/24614http://secunia.com/advisories/16340http://secunia.com/secunia_research/2005-38/advisory/http://securitytracker.com/id?1015610http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229919http://www.osvdb.org/23077http://www.osvdb.org/23078http://www.osvdb.org/23079http://www.securityfocus.com/bid/16577http://www.vupen.com/english/advisories/2006/0499https://exchange.xforce.ibmcloud.com/vulnerabilities/24611https://exchange.xforce.ibmcloud.com/vulnerabilities/24613https://exchange.xforce.ibmcloud.com/vulnerabilities/24614
2006-02-13
Published