Cross-site Scripting and Spoofing Vulnerability in Microsoft Exchange Server 5.5 Service Pack 4 (SP4) with Microsoft Outlook Web Access (OWA)

A cross-site scripting and spoofing vulnerability in Exchange 5.5 SP4 could let an attacker convince an OWA user to run a malicious script.

Ken Pfeil

August 10, 2004

1 Min Read
ITPro Today logo

Reported August 10, 2004, byMicrosoft

VERSIONS AFFECTED

DESCRIPTION
A cross-site scripting and spoofing vulnerability in Exchange 5.5 SP4 could letan attacker convince an OWA user to run a malicious script. This vulnerabilitycould let an attacker access any data on the OWA server that the user could access.

VENDOR RESPONSE
Microsoft has releasedbulletin MS04-026, "Vulnerability in Exchange Server 5.5Outlook Web Access Could Allow Cross-Site Scripting and Spoofing Attacks(842436)," to address this vulnerability and recommends that affectedusers apply the appropriate patch listed in the bulletin.

CREDIT
Discovered by Microsoft.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like