First published: Mon Nov 10 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to qpconfig_sample.xml, aka SPR CWIR7KMPVP and THES7F9NVR, a different vulnerability than CVE-2008-2163 and CVE-2008-3860.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus | <=quickr | |
IBM Lotus | =quickr-8.1 | |
IBM Lotus Domino |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5011 is categorized as a critical vulnerability due to its potential for remote exploitation through cross-site scripting.
To fix CVE-2008-5011, you should upgrade IBM Lotus Quickr to version 8.1.0.2 or later.
The potential impacts of CVE-2008-5011 include the ability for attackers to execute arbitrary web scripts or HTML, potentially compromising user data.
CVE-2008-5011 affects IBM Lotus Quickr versions prior to 8.1.0.2.
No, IBM Lotus Domino itself is not directly vulnerable to CVE-2008-5011.