CVE-2006-0663

IBM Lotus Domino iNotes Client 6.5.4 and 7.0 - Cross-Site Scripting via Email Subject, URI, or Attachment Filename

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-0663. PoCs published by Jakob Balle.

AI-analyzed exploit summary This proof-of-concept demonstrates an HTML and script injection vulnerability in IBM Lotus Domino iNotes. The exploit leverages improper input validation in the email subject field to inject arbitrary JavaScript, which can be used to steal authentication credentials.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java
script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Jakob Balle · textremotemultiple
https://www.exploit-db.com/exploits/27182

This proof-of-concept demonstrates an HTML and script injection vulnerability in IBM Lotus Domino iNotes. The exploit leverages improper input validation in the email subject field to inject arbitrary JavaScript, which can be used to steal authentication credentials.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: IBM Lotus Domino iNotes
No auth needed
Prerequisites: Access to the iNotes web interface
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Jakob Balle · textremotemultiple
https://www.exploit-db.com/exploits/27181

The exploit demonstrates an HTML and script injection vulnerability in IBM Lotus Domino iNotes via a 'javascript:' URI. The proof-of-concept shows how an attacker can inject arbitrary JavaScript code, potentially leading to theft of authentication credentials.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: IBM Lotus Domino iNotes
No auth needed
Prerequisites: Victim interaction (e.g., clicking a malicious link)
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (12)

Core 12
Core References
Patch, Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2005-38/advisory/
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0499
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24614
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24611
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/23079
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/23077
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16577
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/23078
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24613
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16340
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015610

Scores

EPSS 0.0556
EPSS Percentile 91.9%

Details

CWE
CWE-79
Status published
Products (2)
ibm/lotus_domino_inotes_client 6.5.4
ibm/lotus_domino_inotes_client 7.0
Published Feb 13, 2006
Tracked Since Feb 18, 2026