Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2013-0503
Disclosure Date: April 23, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-1032
Disclosure Date: February 15, 2011 (last updated October 04, 2023)
IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.
0
Attacker Value
Unknown
CVE-2011-1030
Disclosure Date: February 14, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Confirm New Page scene."
0
Attacker Value
Unknown
CVE-2010-2278
Disclosure Date: June 15, 2010 (last updated October 04, 2023)
The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
0
Attacker Value
Unknown
CVE-2010-2280
Disclosure Date: June 15, 2010 (last updated October 04, 2023)
Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "mobile edit actions," aka SPR ASRE83PPVH.
0
Attacker Value
Unknown
CVE-2010-2277
Disclosure Date: June 15, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.
0
Attacker Value
Unknown
CVE-2010-2279
Disclosure Date: June 15, 2010 (last updated October 04, 2023)
The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2009-3816
Disclosure Date: October 28, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-3469
Disclosure Date: September 29, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
0
Attacker Value
Unknown
CVE-2008-4809
Disclosure Date: October 31, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors related to "Active" content. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0