Description
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
https://www.exploit-db.com/exploits/25944
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1014440
Vendor Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2005-07/0075.html
Scores
EPSS
0.1319
EPSS Percentile
94.2%
Details
Status
published
Products (1)
ibm/lotus_notes
Published
Jul 09, 2005
Tracked Since
Feb 18, 2026