First published: Sat Nov 10 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino | =7.0 | |
IBM Lotus Domino | =7.0.2 | |
IBM Lotus Domino | <=6.5.6 | |
IBM Lotus Domino | =7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5924 is considered to have a medium severity due to the potential for cross-site scripting attacks.
To fix CVE-2007-5924, upgrade to IBM Lotus Domino version 6.5.6 FP2 or 7.0.2 FP2 or later.
CVE-2007-5924 affects remote authenticated users on vulnerable versions of IBM Lotus Domino.
CVE-2007-5924 allows attackers to inject arbitrary web scripts or HTML, leading to cross-site scripting (XSS) attacks.
Yes, CVE-2007-5924 requires that the attacker is a remote authenticated user to exploit the vulnerability.