CVE-2010-0927

IBM Lotus Domino <7.0.4, 8.0.2 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action. NOTE: this may overlap CVE-2010-0920.

Scores

EPSS 0.0022
EPSS Percentile 44.8%

Classification

CWE
CWE-79
Status published

Affected Products (12)

ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
n/a/n/a

Timeline

Published Mar 05, 2010
Tracked Since Feb 18, 2026