{"api_version":"1","generated_at":"2026-07-23T02:35:44+00:00","cve":"CVE-2001-0726","urls":{"html":"https://cve.report/CVE-2001-0726","api":"https://cve.report/api/cve/CVE-2001-0726.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-0726","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-0726"},"summary":{"title":"CVE-2001-0726","description":"Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-12-06 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/3650","name":"http://www.securityfocus.com/bid/3650","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Microsoft OWA Server Embedded Script Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Microsoft Security Bulletin MS01-057 - Moderate | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/5557","name":"http://www.osvdb.org/5557","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7663","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7663","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-0726","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-0726","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"726","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:30:06.045Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"exchange-owa-embedded-script-execution(7663)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7663"},{"name":"MS01-057","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057"},{"name":"5557","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/5557"},{"name":"3650","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3650"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-12-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-06-16T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"exchange-owa-embedded-script-execution(7663)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7663"},{"name":"MS01-057","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057"},{"name":"5557","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/5557"},{"name":"3650","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3650"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-0726","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"exchange-owa-embedded-script-execution(7663)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7663"},{"name":"MS01-057","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057"},{"name":"5557","refsource":"OSVDB","url":"http://www.osvdb.org/5557"},{"name":"3650","refsource":"BID","url":"http://www.securityfocus.com/bid/3650"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-0726","datePublished":"2002-06-25T04:00:00.000Z","dateReserved":"2001-09-27T00:00:00.000Z","dateUpdated":"2024-08-08T04:30:06.045Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-12-06 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*","matchCriteriaId":"B4F9C143-4734-4E5D-9281-F51513C5CAAF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"726","Ordinal":"1","Title":"CVE-2001-0726","CVE":"CVE-2001-0726","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"726","Ordinal":"1","NoteData":"Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.","Type":"Description","Title":"CVE-2001-0726"},{"CveYear":"2001","CveId":"726","Ordinal":"2","NoteData":"2002-06-25","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"726","Ordinal":"3","NoteData":"2002-06-15","Type":"Other","Title":"Modified"}]}}}