CVE-2006-1948
Last modified
CVE-2006-1948 is a vulnerability of currently unknown severity. The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauthorized recipient.. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauthorized recipient.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Lotus Notes | 6.0 |
| Ibm | Lotus Notes | 6.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1948?
How severe is CVE-2006-1948?
How do I fix CVE-2006-1948?
Are you affected by CVE-2006-1948?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
