Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Lotus Domino File Disclosure Vulnerability

Lotus Domino is an application server developed by IBM. One of it's features is that it allows for remote user interaction with a Lotus Notes database via a web-based interface.

By specifying it's Replica ID, an attacker can successfully request the Web Administrator template. Access to this template file may allow for an attacker to view the contents of arbitrary webserver-readable files on the filesystem.







 

Privacy Statement
Copyright 2009, SecurityFocus