PT-2004-1368 · Microsoft · Exchange Server

Amit Klein

·

Published

2004-08-12

·

Updated

2020-04-09

·

CVE-2004-0203

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Exchange Server 5.5 Service Pack 4
Description A cross-site scripting issue allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.
Recommendations For Exchange Server 5.5 Service Pack 4, consider disabling HTML email rendering or restricting access to HTML redirect queries as a temporary workaround until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-0203

Affected Products

Exchange Server