CVE-2011-1106
IBM Lotus Sametime - Stored Cross-Site Scripting via stcenter.nsf authReasonCode Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-1106. PoCs published by andrew.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server by injecting a malicious script via the 'authReasonCode' parameter. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies.
Description
Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in IBM Lotus Sametime Server by injecting a malicious script via the 'authReasonCode' parameter. The script executes arbitrary JavaScript in the context of the affected site, potentially stealing cookies.