vendor:
Lotus Domino Controller
by:
Alexey Sintsov
9
CVSS
(CVSS2)
Authentication Bypass
287
CWE
Product Name: Lotus Domino Controller
Affected Version From: <=8.5.2 FP3
Affected Version To: <=8.5.3
Patch Exists: YES
Related CWE: CVE-2011-1519
CPE: 2.3:a:ibm:lotus_domino_controller:8.5.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 / Windows 2008
2011
IBM Lotus Domino Controller auth. bypass
This bug was found by Patrik Karlsson and sold to ZDI. IBM make fix for this bug, but not enough. So this sploit can make auth. bypass in Lotus Domino Controller even with patch from IBM. So still 0day. Details can be found at http://dsecrg.com/pages/pub/show.php?id=41. The exploit involves making a port-fwd from 127.0.0.1:2050 to REMOTE_TARGET:2050, injecting XML into IIS log file, and running a script from a local web-server.
Mitigation:
IBM has released a patch for this vulnerability.