>> IBM Lotus Quickr Denial of Service and Security Bypass Vulnerabilities
Title : IBM Lotus Quickr Denial of Service and Security Bypass Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2753 CVE ID : GENERIC-MAP-NOMATCH CWE ID : CWE-20 -
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-07
Technical Description
Multiple vulnerabilities have been identified in IBM Lotus Quickr, which could be exploited by attackers or malicious users to cause a denial of service or bypass security restrictions.
The first issue is caused by an input validation error when processing a non-standard URL argument for OpenDocument command, which could be exploited to crash a vulnerable server, creating a denial of service condition.
The second vulnerability is caused by an error where a place manager can demote or delete a place superuser group.
The third issue is caused by an error where an editor can delete pages created by a different author.