CVE-2006-0663
IBM Lotus Domino iNotes Client 6.5.4 and 7.0 - Cross-Site Scripting via Email Subject, URI, or Attachment Filename
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-0663. PoCs published by Jakob Balle.
AI-analyzed exploit summary This proof-of-concept demonstrates an HTML and script injection vulnerability in IBM Lotus Domino iNotes. The exploit leverages improper input validation in the email subject field to inject arbitrary JavaScript, which can be used to steal authentication credentials.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.
Exploits (2)
This proof-of-concept demonstrates an HTML and script injection vulnerability in IBM Lotus Domino iNotes. The exploit leverages improper input validation in the email subject field to inject arbitrary JavaScript, which can be used to steal authentication credentials.
The exploit demonstrates an HTML and script injection vulnerability in IBM Lotus Domino iNotes via a 'javascript:' URI. The proof-of-concept shows how an attacker can inject arbitrary JavaScript code, potentially leading to theft of authentication credentials.