Lucene search

K
cve[email protected]CVE-2010-0920
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-0920

2022-10-0316:21:13
CWE-79
web.nvd.nist.gov
16
ibm
lotus
inotes
xss
vulnerability
domino
web access
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.8%

Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of “XSS/CSRF Get Filter and Referer Check fixes.”

Affected configurations

NVD
Node
ibmlotus_inotesRange229.271
OR
ibmlotus_inotesMatch229.011
OR
ibmlotus_inotesMatch229.021
OR
ibmlotus_inotesMatch229.031
OR
ibmlotus_inotesMatch229.041
OR
ibmlotus_inotesMatch229.051
OR
ibmlotus_inotesMatch229.061
OR
ibmlotus_inotesMatch229.101
OR
ibmlotus_inotesMatch229.111
OR
ibmlotus_inotesMatch229.131
OR
ibmlotus_inotesMatch229.141
OR
ibmlotus_inotesMatch229.151
OR
ibmlotus_inotesMatch229.161
OR
ibmlotus_inotesMatch229.171
OR
ibmlotus_inotesMatch229.181
OR
ibmlotus_inotesMatch229.191
OR
ibmlotus_inotesMatch229.201
OR
ibmlotus_inotesMatch229.211
OR
ibmlotus_inotesMatch229.221
OR
ibmlotus_inotesMatch229.231
OR
ibmlotus_inotesMatch229.241
OR
ibmlotus_inotesMatch229.251
OR
ibmlotus_inotesMatch229.261
AND
ibmlotus_dominoMatch8.0.2.4

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.8%

Related for CVE-2010-0920