CVE-2005-2428 Scanner

Detects 'Information Disclosure' vulnerability in BM Lotus Domino affects v. 5.0, 6.0, 6.5.0.


CVE-2005-2428 Scanner Detail

IBM Lotus Domino is a platform used for enterprise email, messaging, and collaboration purposes. It includes a directory database, names.nsf, which is used as a Public Address Book. The directory database provides a way to look up users and their contact information, including email addresses and phone numbers. The platform is widely used in large organizations and companies across the world.

The CVE-2005-2428 vulnerability is a critical flaw detected in the names.nsf directory database. The vulnerability allows a remote attacker to access sensitive information, including usernames, password hashes, client's platform, machine name, and Lotus Domino release information. A remote attacker can exploit this vulnerability by viewing the HTML source code. Since the directory database is readable by default, it can easily be accessed by any remote attacker.

Exploiting this vulnerability can lead to serious data breaches in large organizations. Attackers can extract sensitive information and use it for malicious purposes, including stealing intellectual property, gaining unauthorized access to corporate systems, or launching targeted attacks against specific individuals or groups in the organization.



