Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24612
http://www.vupen.com/english/advisories/2006/0499
http://www.securityfocus.com/bid/16577
http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229919
http://securitytracker.com/id?1015610