PT-2001-1908 · Microsoft · Internet Explorer+2
Published
2001-12-06
·
Updated
2020-04-09
·
CVE-2001-0726
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Exchange 5.5 Server
Description:
The issue concerns the improper detection of certain inline scripts by Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server when used with Internet Explorer. This can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
Recommendations:
For Microsoft Exchange 5.5 Server, consider disabling the use of inline scripts in HTML e-mail messages as a temporary workaround until a patch is available. Restrict access to sensitive mailbox operations to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer
Exchange 5.5 Server
Outlook Web Access