CVE-2001-1161
Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.64% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- lotus/domino r5 server
- Source
- cve@mitre.org
References
- http://www.iss.net/security_center/static/6789.phpPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/642239Third Party Advisory, US Government Resource
- http://www.osvdb.org/1887
- http://www.securityfocus.com/archive/1/194465Vendor Advisory
- http://www.securityfocus.com/archive/1/194609
- http://www.securityfocus.com/bid/2962Vendor Advisory
- http://www.iss.net/security_center/static/6789.phpPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/642239Third Party Advisory, US Government Resource
- http://www.osvdb.org/1887
- http://www.securityfocus.com/archive/1/194465Vendor Advisory
- http://www.securityfocus.com/archive/1/194609
- http://www.securityfocus.com/bid/2962Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.