CVE-2004-2310

IBM Lotus Domino R6 6.5.1 - Cross-Site Scripting via Quick Console Domino Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-2310. PoCs published by dr_insane.

AI-analyzed exploit summary This is a writeup describing a cross-site scripting (XSS) vulnerability in IBM Lotus Domino server's 'Quick Console' function. The vulnerability allows execution of arbitrary script code in the context of a user's browser session.

Description

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.

Exploits (1)

exploitdb WRITEUP VERIFIED
by dr_insane · textremotewindows
https://www.exploit-db.com/exploits/23837

This is a writeup describing a cross-site scripting (XSS) vulnerability in IBM Lotus Domino server's 'Quick Console' function. The vulnerability allows execution of arbitrary script code in the context of a user's browser session.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: IBM Lotus Domino server 6.5.1
Auth required
Prerequisites: Access to the administrative interface · Valid credentials for authentication
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9901
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15502
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11143
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/4306

Scores

EPSS 0.0361
EPSS Percentile 88.0%

Details

Status published
Products (1)
ibm/lotus_domino 6.5.1
Published Dec 31, 2004
Tracked Since Feb 18, 2026