Description: Some vulnerabilities have been reported in IBM Lotus Domino, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially compromise a vulnerable system.
1) A boundary error within the Lotus Domino Web Server can be exploited to cause a stack-based buffer overflow via a specially crafted HTTP request with an overly long "Accept-Language" header.
Successful exploitation may allow execution of arbitrary code.
2) Certain unspecified input passed to the servlet engine/Web container is not properly sanitised before being used. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Solution: Update to version 7.0.3 Fix Pack 1 (FP1) or 8.0.1.
Provided and/or discovered by: 1) MWR InfoSecurity
2) Reported by the vendor.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.