Lotus Domino Server Multiple Information Disclosure Vulnerabilities

Low Nessus Network Monitor Plugin ID 3114


The remote host may give an attacker information useful for future attacks.


The remote host is running a version of Lotus Domino Server that is prone to several information disclosure vulnerabilities. Specifically, users' password hashes and other data are included in hidden fields in the public address book 'names.nsf' that is readable by default by all users. Moreover, Domino does not use a 'salt' to compute password hashes, which makes it easier to crack passwords.


Upgrade to version 6.5.5, 6.0.6 or higher.

See Also


Plugin Details

Severity: Low

ID: 3114

Family: Web Servers

Published: 2005/07/26

Modified: 2018/09/16

Dependencies: 1442

Nessus ID: 19309

Risk Information

Risk Factor: Low


Base Score: 2.7

Temporal Score: 2.6

Vector: CVSS2#AV:A/AC:L/Au:S/C:P/I:N/A:N

Temporal Vector: CVSS2#E:H/RL:W/RC:ND


Base Score: 3.5

Temporal Score: 3.4


Temporal Vector: CVSS3#E:H/RL:W/RC:X

Vulnerability Information

CPE: cpe:/a:ibm:lotus_domino

Exploitable With

CANVAS (D2ExploitPack)

Reference Information

CVE: CVE-2005-2428

BID: 14388, 14389