Collected research
Lotus Notes Formula Injection
New security vulnerability: Lotus Notes Formula Injection
A code review of IBM's Domino Blog application found HTTP request data reaching LotusScript's Evaluate function without encoding, letting an attacker inject Lotus Notes Formula statements. The sample payload wraps @MailSend so the Domino server emails data out, and the formula language's breadth extends that towards full server compromise. Disclosed to IBM in April 2010.
Record
- Document
- New security vulnerability: Lotus Notes Formula Injection
- Published by
- aboulton.blogspot.com
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of aboulton.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .