This script is Copyright (C) 2005-2011 Tenable Network Security, Inc.
The remote web server is affected by multiple information disclosure
The remote host is running a version of Lotus Domino Server that is
prone to several information disclosure vulnerabilities.
Specifically, users' password hashes and other data are included in
hidden fields in the public address book 'names.nsf' readable by
default by all users. Moreover, Domino does not use a 'salt' to
compute password hashes, which makes it easier to crack passwords.
See also :
Upgrade to Lotus Domino Server version 6.0.6 / 6.5.5 or later.
Risk factor :
Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 4.8
Public Exploit Available : true
Family: Web Servers
Nessus Plugin ID: 19309 (domino_http_info_disclosure.nasl)
Bugtraq ID: 1438814389
CVE ID: CVE-2005-2428
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.