notes question

From: otaner@gmx.ch
Date: 11/23/01


Date: Fri, 23 Nov 2001 19:03:28 +0100 (MET)
From: otaner@gmx.ch
To: pen-test@securityfocus.com
Subject: notes question
Message-ID: <7676.1006538608@www30.gmx.net>

Hi,

During a pentest, I found a notes server with some vulnerabilities and one
of these bugs let me access the webadmin.ntf as the anonymous user. I'm not
sure, but it seems that this problem was discussed in the following article on
bugtraq:

Title: Lotus Domino Web Administrator Template ReplicaID Access
Link: http://www.securityfocus.net/archive/1/223812

Has anybody experience with that problem? What are the next steps to gain
more privilegs?

any help would be appreciated

regards
Renato

-- 
GMX - Die Kommunikationsplattform im Internet.
http://www.gmx.net

---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/



Relevant Pages

  • RE: Laboratory Setup Help (RS)
    ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >> vulnerabilities please see: ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Cross Site Scripting Vulnerabilities - XSS
    ... Cross Site Scripting Vulnerabilities - XSS ... >> This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Cross Site Scripting Vulnerabilities - XSS
    ... Cross Site Scripting Vulnerabilities - XSS ... >>> This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: Vulnebrability level definition
    ... 'severity' of a given vulnerability, and this severity can change with time. ... different methodologies to rate vulnerabilities and present the associated ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Scanners and unpublished vulnerabilities - Full Disclosure
    ... AH> vulnerabilities they have notified vendors about. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)