CVE-2013-4063

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:lotus_domino:8.5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:8.5.3.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino:9.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_inotes:8.5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_inotes:8.5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_inotes:8.5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_inotes:8.5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_inotes:8.5.3.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_inotes:8.5.3.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_inotes:9.0.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-12-21 14:22

Updated : 2024-02-28 12:00


NVD link : CVE-2013-4063

Mitre link : CVE-2013-4063

CVE.ORG link : CVE-2013-4063


JSON object : View

Products Affected

ibm

  • lotus_domino
  • lotus_inotes
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')