CVE-2005-3015: XSS
Published Sep 21, 2005
·Updated
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.
Affected Software
2 affected components
IBM Lotus Domino=6.5.2
IBM Lotus Domino Enterprise Server=6.5.2
Remediation
Patch Available
Patch Available
Event History
Sep 21, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3015?
The severity of CVE-2005-3015 is considered moderate due to its ability to allow cross-site scripting attacks.
2
How do I fix CVE-2005-3015?
To fix CVE-2005-3015, update to a patched version of IBM Lotus Domino that addresses this vulnerability.
3
Which versions of IBM Lotus Domino are affected by CVE-2005-3015?
IBM Lotus Domino versions 6.5.2 and IBM Lotus Domino Enterprise Server 6.5.2 are affected by CVE-2005-3015.
4
What types of attacks can CVE-2005-3015 enable?
CVE-2005-3015 can enable remote attackers to perform cross-site scripting attacks by injecting arbitrary web script or HTML.
5
Is there a workaround for CVE-2005-3015 if I cannot update?
A temporary workaround for CVE-2005-3015 may include sanitizing or validating user input for the BaseTarget and Src parameters.