S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2005-2428 Scanner

CVE-2005-2428 scanner - Information Disclosure vulnerability in BM Lotus Domino

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
5.0
CVSS
Description

Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

IBM Lotus Domino is a platform used for enterprise email, messaging, and collaboration purposes. It includes a directory database, names.nsf, which is used as a Public Address Book. The directory database provides a way to look up users and their contact information, including email addresses and phone numbers. The platform is widely used in large organizations and companies across the world.

The CVE-2005-2428 vulnerability is a critical flaw detected in the names.nsf directory database. The vulnerability allows a remote attacker to access sensitive information, including usernames, password hashes, client's platform, machine name, and Lotus Domino release information. A remote attacker can exploit this vulnerability by viewing the HTML source code. Since the directory database is readable by default, it can easily be accessed by any remote attacker.

Exploiting this vulnerability can lead to serious data breaches in large organizations. Attackers can extract sensitive information and use it for malicious purposes, including stealing intellectual property, gaining unauthorized access to corporate systems, or launching targeted attacks against specific individuals or groups in the organization.

s4e.io is an online platform that provides information about cybersecurity vulnerabilities and risks. Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets, assess their risk levels, and take appropriate actions to mitigate them. With this platform, readers can protect their organizations against various digital threats and stay ahead of potential cybersecurity attacks.

 

REFERENCES

Solution Advice

To hide the HTTP password from the HTML source:

  • Open the $PersonalInheritableSchema subform (In the designer under Shared Code, Subforms).
  • Find the fields: $dspHTTPPassword and HTTPPassword.
  • In the field properties for both fields, on the hide tab under "Hide paragram from" check off "Web browsers".
  • Open the Person form (Under Forms).
  • In the form properties, on the 2nd tab, disable the option "Generate HTML for all fields".

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2005-2428 scanner - Information Disclosure vulnerability in BM Lotus Domino | S4E