PT-2008-3743 · Microsoft · Outlook Web Access+1
Michael Jordan
·
Publicado
2008-07-08
·
Atualizado
2020-04-09
·
CVE-2008-2248
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Outlook Web Access (OWA) for Exchange Server 2003 SP2
Description:
The issue is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML. Exploitation could lead to elevation of privilege on individual OWA clients, enabling actions such as reading, sending, and deleting email as the logged-on user. This can be achieved by convincing a user to open a specially crafted email that runs malicious script within an individual OWA client.
Recommendations:
For Outlook Web Access (OWA) for Exchange Server 2003 SP2, consider restricting access to potentially vulnerable HTML elements until a patch is available. As a temporary workaround, avoid using OWA to open suspicious or unsolicited emails.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Exchange Server
Outlook Web Access