CVE-2010-0920
IBM Lotus iNotes <229.281 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."
Scores
EPSS
0.0029
EPSS Percentile
52.0%
Classification
CWE
CWE-79
Status
published
Affected Products (24)
ibm/lotus_inotes
< 229.271
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
ibm/lotus_inotes
... and 9 more
Timeline
Published
Mar 03, 2010
Tracked Since
Feb 18, 2026