Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.14254
Category:Windows : Microsoft Bulletins
Title:Vulnerability in Exchange Server 5.5 Outlook Web Access XSS (842436)
Summary:The remote host is running a version of the Outlook Web Access which contains; cross site scripting flaws.
Description:Summary:
The remote host is running a version of the Outlook Web Access which contains
cross site scripting flaws.

Vulnerability Impact:
This vulnerability could allow an attacker to convince a user
to run a malicious script. If this malicious script is run, it would execute
in the security context of the user.
Attempts to exploit this vulnerability require user interaction.

This vulnerability could allow an attacker access to any data on the
Outlook Web Access server that was accessible to the individual user.

It may also be possible to exploit the vulnerability to manipulate Web browser caches
and intermediate proxy server caches, and put spoofed content in those caches.

Solution:
Apply the Windows Updates described in the references.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0203
CERT/CC vulnerability note: VU#948750
http://www.kb.cert.org/vuls/id/948750
Microsoft Security Bulletin: MS04-026
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-026
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2016
XForce ISS Database: exchange-owa-execute-code(16583)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16583
CopyrightCopyright (C) 2004 David Maciejak

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.