CVE-2012-3302 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.

Reference

http://websecurity.com.ua/5839/ http://www-01.ibm.com/support/docview.wss?uid=swg21608160 https://exchange.xforce.ibmcloud.com/vulnerabilities/77401

Share on: