lotusTimeout.txt...

- AV AC AU C I A
发布: 2006-09-13
修订: 2025-04-13

In Lotus Domino Web Access (DWA) version 7.0.1, the session token used to identify the user (called "LtpaToken") is not invalidated on the server upon user logout. The cookie is removed from the browser, but the token continues to be recognized by the server until a configurable expiration time is reached.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息