Description
This script is vulnerable to Lotus Notes Formula Injection.
Lotus Notes Formula Injection is a vulnerability that allows an attacker to alter Lotus Notes Formula statements by manipulating the user input. Lotus Notes Formula Injection occurs when web applications accept user input that is directly placed into the Evaluate function from LotusScript. Consult References for more information about this vulnerability.
Remediation
Your script should filter metacharacters from user input.
References
Related Vulnerabilities
Umbraco CMS remote code execution
Ruby on Rails weak/known secret token
WordPress Plugin Store Locator Plus for WordPress Multiple Vulnerabilities (3.0.1)
WordPress Plugin SP Project & Document Manager Multiple SQL Injection Vulnerabilities (2.4.3)
WordPress Plugin WordPress Clean Up & Optimizer-Clean Up Optimizer SQL Injection (3.0.13)