Home > Domino News > Minor Notes/Domino scripting vulnerability reported
Domino News:
EMAIL THIS

Minor Notes/Domino scripting vulnerability reported

By Eric B. Parizo, News Editor
21 Oct 2004 | SearchDomino.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

According to security Web sites, a newly discovered vulnerability could leave Lotus Notes and Domino vulnerable to certain attacks, even though the exploit is considered minor.

Both the Secunia and the SecurityFocus Bugtraq Web sites report that a cross-site scripting vulnerability has been found in Notes version 6.x and Domino 6. Other versions may be affected as well.

For more information

Learn about Java applet flaws found in Notes.

Read our exclusive on a pair of recent Notes/Domino flaws.

The vulnerability, according to reports, is caused by an input validation error in native Lotus Notes HTML encoding for computed values, where specially crafted input with square brackets is not properly sanitized before being returned to the user.

As a result, the problem can be exploited to execute arbitrary HTML and script code in a user's browser session in context of a vulnerable site.

The vulnerability has been classified as "less critical," and can be avoided by ensuring that inputs containing square brackets are properly sanitized. Additionally, exploitation is reportedly not possible on editable fields.

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Lotus Notes Server Solutions - Quickr, Domino Server, Websphere
HomeTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersDomino IT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts