
Shalom Carmel has reported <A HREF="http://secunia.com/advisories/15778/">a vulnerability</A> in Lotus Domino, which can be exploited by malicious people to conduct script insertion attacks. The vulnerability is caused due to Domino failing to prompt users for actions before displaying a HTML attachment in a browser. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site when the HTML attachment is opened.