{"api_version":"1","generated_at":"2026-07-23T04:53:23+00:00","cve":"CVE-2003-0712","urls":{"html":"https://cve.report/CVE-2003-0712","api":"https://cve.report/api/cve/CVE-2003-0712.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0712","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0712"},"summary":{"title":"CVE-2003-0712","description":"Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-11-17 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/435444","name":"http://www.kb.cert.org/vuls/id/435444","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"CERT/CC Vulnerability Note VU#435444","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/8832","name":"http://www.securityfocus.com/bid/8832","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","VDB Entry"],"title":"Microsoft Exchange Server 5.5 Outlook Web Access Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-047","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-047","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Microsoft Security Bulletin MS03-047 - Moderate | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=106631918405915&w=2","name":"http://marc.info/?l=bugtraq&m=106631918405915&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"'Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cert.org/advisories/CA-2003-27.html","name":"http://www.cert.org/advisories/CA-2003-27.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"CERT Advisory CA-2003-27 Multiple Vulnerabilities in Microsoft Windows and Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0712","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0712","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"712","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"712","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"712","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"712","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"712","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"sp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:05:12.423Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"CA-2003-27","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.cert.org/advisories/CA-2003-27.html"},{"name":"20031016 Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=106631918405915&w=2"},{"name":"8832","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/8832"},{"name":"VU#435444","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/435444"},{"name":"MS03-047","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-047"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-10-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"CA-2003-27","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.cert.org/advisories/CA-2003-27.html"},{"name":"20031016 Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=106631918405915&w=2"},{"name":"8832","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/8832"},{"name":"VU#435444","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/435444"},{"name":"MS03-047","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-047"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0712","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"CA-2003-27","refsource":"CERT","url":"http://www.cert.org/advisories/CA-2003-27.html"},{"name":"20031016 Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=106631918405915&w=2"},{"name":"8832","refsource":"BID","url":"http://www.securityfocus.com/bid/8832"},{"name":"VU#435444","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/435444"},{"name":"MS03-047","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-047"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0712","datePublished":"2003-10-17T04:00:00.000Z","dateReserved":"2003-09-02T00:00:00.000Z","dateUpdated":"2024-08-08T02:05:12.423Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-11-17 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*","matchCriteriaId":"B4F9C143-4734-4E5D-9281-F51513C5CAAF"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*","matchCriteriaId":"AD3E2F18-A369-4767-ACEF-38DB40EEC6D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*","matchCriteriaId":"EC01670D-4550-4034-86A5-7879B6334241"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*","matchCriteriaId":"B80A57A1-7B9F-4C07-ADAA-DBC4687F1EFC"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*","matchCriteriaId":"E3983529-F4E3-4883-97AF-5BFC87AC3E86"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"712","Ordinal":"1","Title":"CVE-2003-0712","CVE":"CVE-2003-0712","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"712","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.","Type":"Description","Title":"CVE-2003-0712"},{"CveYear":"2003","CveId":"712","Ordinal":"2","NoteData":"2003-10-17","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"712","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}