CVE-2007-0977 Information

Description

IBM Lotus Domino R5 and R6 WebMail with \Generate HTML for all fields\ enabled stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view a different vector than CVE-2005-2428.

Reference

http://osvdb.org/35764 https://www.exploit-db.com/exploits/3302

Share on: