PT-2001-1908 · Microsoft · Internet Explorer+2
Publicado
2001-12-06
·
Atualizado
2020-04-09
·
CVE-2001-0726
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Exchange 5.5 Server
Description:
The issue concerns the improper detection of certain inline scripts by Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server when used with Internet Explorer. This can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
Recommendations:
For Microsoft Exchange 5.5 Server, consider disabling the use of inline scripts in HTML e-mail messages as a temporary workaround until a patch is available. Restrict access to sensitive mailbox operations to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer
Exchange 5.5 Server
Outlook Web Access