CVE Database
/

CVE-2005-2428

Back to search

CVE-2005-2428

Published: Aug 3, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.

VendorProductVersions

n/a

n/a

affected
n/a

References

14389
vdb-entry
x_refsource_BID
39495
exploit
x_refsource_EXPLOIT-DB
1014584
vdb-entry
x_refsource_SECTRACK
18462
vdb-entry
x_refsource_OSVDB
16231
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now