Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/311806 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11311 | vdb entry |
http://www.securityfocus.com/bid/6841 | vdb entry |
http://www.securityfocus.com/archive/1/311660 | mailing list exploit |