CVE-2005-2175
IBM Lotus Notes - Unauthenticated Cookie Theft via Automatic HTML Attachment Processing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2175. PoCs published by [email protected].
AI-analyzed exploit summary This exploit demonstrates an XSS vulnerability in IBM Lotus Notes email client by embedding malicious JavaScript in an HTML attachment. The script executes automatically when the email is viewed, potentially stealing cookies or performing other malicious actions.
Description
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
Exploits (1)
This exploit demonstrates an XSS vulnerability in IBM Lotus Notes email client by embedding malicious JavaScript in an HTML attachment. The script executes automatically when the email is viewed, potentially stealing cookies or performing other malicious actions.