AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-2428

MEDIUM · CVSS 5 EPSS 73.03% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-08-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2005-2428
Severity
MEDIUM
CVSS
5
EPSS
73.03%

Original NVD Description

Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.