PoC Index

CVE-2011-1519

HIGH 10.0EPSS 9.2%

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
9.20% chance of exploitation in the next 30 days, 95th percentile
Published
2011-03-25
Updated
2024-08-06

ExploitDB entries (1)

References

Related