CVE-2004-0480

IBM Lotus Notes <6.5 - Command Injection

Title source: llm

Description

Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.

Scores

EPSS 0.1950
EPSS Percentile 95.3%

Classification

CWE
CWE-88
Status draft

Affected Products (2)

ibm/lotus_notes
ibm/lotus_notes

Timeline

Published Dec 06, 2004
Tracked Since Feb 18, 2026