About Duffbert...

Duffbert's Random Musings is a blog where I talk about whatever happens to be running through my head at any given moment... I'm Thomas Duff, and you can find out more about me here...

Email Me!

Search This Site!

Custom Search

I'm published!

Co-author of the book IBM Lotus Sametime 8 Essentials: A User's Guide
SametimeBookCoverImage.jpg

Purchase on Amazon

Co-author of the book IBM Sametime 8.5.2 Administration Guide
SametimeAdminBookCoverImage.jpg

Purchase on Amazon

MiscLinks

Visitor Count...



View My Stats

« Book Review - Freedom (TM) by Daniel Suarez | Main| Book Review - The Backchannel: How Audiences are Using Twitter and Social Media and Changing Presentations Forever by Cliff Atkinson »

IBM Lotus Notes 'names.nsf' Open Redirection Vulnerability

Category IBM/Lotus
From SecurityFocus: IBM Lotus Notes 'names.nsf' Open Redirection Vulnerability

Bugtraq ID: 38852 Class: Input Validation Error CVE: Remote: Yes Local: No Published: Mar 19 2010 12:00AM Updated: Mar 19 2010 12:00AM Credit: Yaniv Miron aka "Lament" Vulnerable: IBM Lotus Notes 6.5.6
IBM Lotus Notes 6.5.5
IBM Lotus Notes 6.5.4
IBM Lotus Notes 6.5.3
IBM Lotus Notes 6.5.2
IBM Lotus Notes 6.5.1
IBM Lotus Notes 6.5
IBM Lotus Notes 6.0.5
IBM Lotus Notes 6.0.4
IBM Lotus Notes 6.0.3
IBM Lotus Notes 6.0.2
IBM Lotus Notes 6.0.1
IBM Lotus Notes 6.0
IBM Lotus Notes 6.5.6 FP2
IBM Lotus Notes 6.5.5 FP3
IBM Lotus Notes 6.5.5 FP2

Not Vulnerable:

IBM Lotus Notes is prone to an open-redirection vulnerability because the application fails to properly sanitize user-supplied input.

A successful exploit may aid in phishing attacks; other attacks are possible.

Lotus Notes 6.x is vulnerable; other versions may also be affected.


An attacker can exploit this issue by enticing an unsuspecting victim into following a malicious URI.

The following example POST data is available:

POST /names.nsf?Login HTTP/1.1

Connection: Keep-Alive

%25%25ModDate=xxxxxxxxxxxxxxxx&Username=yyyy+zzzz&Password=aaaaaa&RedirectTo=http://www.example.com&SaveOptions=0&...


Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.


References:

Post A Comment

:-D:-o:-p:-x:-(:-):-\:angry::cool::cry::emb::grin::huh::laugh::lips::rolleyes:;-)

Want to support this blog or just say thanks?

When you shop Amazon, start your shopping experience here.

When you do that, all your purchases during that session earn me an affiliate commission via the Amazon Affiliate program. You don't have to buy the book I linked you to (although I wouldn't complain!). Simply use that as your starting point.

Thanks!

Thomas "Duffbert" Duff

Ads of Relevance...