Nessus Plugin #10629

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Lotus Domino administration databases

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2001 Javier Fernßndez-Sanguino Pe±a
Summary:
Checks if Lotus Domino administration databases can be anonymously accessed
Version:
$Revision: 1.29 $
Cve_id:
CAN-2000-0021, CAN-2002-0664
Bugtraq_id:
5101, 881
Xrefs:
-
Description:

This script determines if some default databases can be read
remotely.

An anonymous user can retrieve information from this
Lotus Domino server: users, databases, configuration
of servers (including operating system and hard
disk partitioning), logs of access to users (which
could expose sensitive data if GET html forms are used)..

This issues are discussed in 'Lotus White Paper:
A Guide to Developing Secure Domino Applications' (december 1999)
http://www.lotus.com/developers/devbase.nsf/articles/doc1999112200

Solution: verify all the ACLs for these databases and remove those not needed

Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.