CVE-2005-2175

Lotus Notes - XSS

Title source: llm
STIX 2.1

Description

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

Exploits (1)

exploitdb WORKING POC VERIFIED
by [email protected] · textremotemultiple
https://www.exploit-db.com/exploits/25944

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014440
Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2005-07/0075.html

Scores

EPSS 0.1319
EPSS Percentile 94.2%

Details

Status published
Products (1)
ibm/lotus_notes
Published Jul 09, 2005
Tracked Since Feb 18, 2026