First published: Thu Sep 20 2001(Updated: )
Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino | =5.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1018 is classified as a medium severity vulnerability.
CVE-2001-1018 allows remote attackers to find out the internal IP address of a Lotus Domino server through a specially crafted GET request.
CVE-2001-1018 affects users running Lotus Domino web server version 5.0.8.
To resolve CVE-2001-1018, it is recommended to upgrade to a more recent and secure version of Lotus Domino.
While CVE-2001-1018 has been known for a long time, any systems still running vulnerable versions remain at risk.