Lucene search

K
cveMitreCVE-2005-2175
HistoryJul 09, 2005 - 4:00 a.m.

CVE-2005-2175

2005-07-0904:00:00
mitre
web.nvd.nist.gov
34
lotus notes
web interface
html processing
attachment
remote attack
cookie theft

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.869

Percentile

98.6%

The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

Affected configurations

Nvd
Node
ibmlotus_notes
VendorProductVersionCPE
ibmlotus_notes*cpe:2.3:a:ibm:lotus_notes:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

High

EPSS

0.869

Percentile

98.6%