source: http://www.securityfocus.com/bid/38852/info IBM Lotus Notes is prone to an open-redirection vulnerability because the application fails to properly sanitize user-supplied input. A successful exploit may aid in phishing attacks; other attacks are possible. Lotus Notes 6.x is vulnerable; other versions may also be affected. The following example POST data is available: POST /names.nsf?Login HTTP/1.1 Connection: Keep-Alive %25%25ModDate=xxxxxxxxxxxxxxxx&Username=yyyy+zzzz&Password=aaaaaa&RedirectTo=http://www.example.com&SaveOptions=0&...