Web Hack List

Collected research

Lotus Notes Formula Injection

New security vulnerability: Lotus Notes Formula Injection

A code review of IBM's Domino Blog application found HTTP request data reaching LotusScript's Evaluate function without encoding, letting an attacker inject Lotus Notes Formula statements. The sample payload wraps @MailSend so the Domino server emails data out, and the formula language's breadth extends that towards full server compromise. Disclosed to IBM in April 2010.

Record

Document
New security vulnerability: Lotus Notes Formula Injection
Published by
aboulton.blogspot.com
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of aboulton.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .