Vulnerability Description
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Lotus Domino | 5.0 |
References
- http://osvdb.org/35764
- https://www.exploit-db.com/exploits/3302
- http://osvdb.org/35764
- https://www.exploit-db.com/exploits/3302
FAQ
What is CVE-2007-0977?
CVE-2007-0977 is a vulnerability with a CVSS score of 7.1 (HIGH). IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to t...
How severe is CVE-2007-0977?
CVE-2007-0977 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0977?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Lotus Domino.