Lucene search

K
nvd[email protected]NVD:CVE-2006-1948
HistoryApr 20, 2006 - 10:02 p.m.

CVE-2006-1948

2006-04-2022:02:00
web.nvd.nist.gov
4

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

56.5%

The “Add Sender to Address Book” operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauthorized recipient.

Affected configurations

Nvd
Node
ibmlotus_notesMatch6.0
OR
ibmlotus_notesMatch6.5
VendorProductVersionCPE
ibmlotus_notes6.0cpe:2.3:a:ibm:lotus_notes:6.0:*:*:*:*:*:*:*
ibmlotus_notes6.5cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

56.5%

Related for NVD:CVE-2006-1948