{"api_version":"1","generated_at":"2026-07-23T05:02:06+00:00","cve":"CVE-2005-0563","urls":{"html":"https://cve.report/CVE-2005-0563","api":"https://cve.report/api/cve/CVE-2005-0563.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0563","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0563"},"summary":{"title":"CVE-2005-0563","description":"Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL (\"jav&#X41sc&#0010;ript:\") in an IMG tag.","state":"PUBLISHED","assigner":"microsoft","published_at":"2005-06-14 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.idefense.com/application/poi/display?id=261&type=vulnerabilities","name":"http://www.idefense.com/application/poi/display?id=261&type=vulnerabilities","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Accenture | Let there be change","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/13952","name":"http://www.securityfocus.com/bid/13952","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Microsoft Exchange Server Outlook Web Access HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/15697","name":"http://secunia.com/advisories/15697","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Secunia - Advisories - Microsoft Outlook Web Access Script Insertion Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-029","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-029","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Microsoft Security Bulletin MS05-029 - Important | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0563","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0563","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"563","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:21:06.600Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"MS05-029","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-029"},{"name":"20050614 Microsoft Outlook Web Access Cross-Site Scripting Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://www.idefense.com/application/poi/display?id=261&type=vulnerabilities"},{"name":"15697","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15697"},{"name":"13952","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13952"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-06-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL (\"jav&#X41sc&#0010;ript:\") in an IMG tag."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2019-05-31T23:06:03.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"MS05-029","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-029"},{"name":"20050614 Microsoft Outlook Web Access Cross-Site Scripting Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://www.idefense.com/application/poi/display?id=261&type=vulnerabilities"},{"name":"15697","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15697"},{"name":"13952","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13952"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2005-0563","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL (\"jav&#X41sc&#0010;ript:\") in an IMG tag."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"MS05-029","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-029"},{"name":"20050614 Microsoft Outlook Web Access Cross-Site Scripting Vulnerability","refsource":"IDEFENSE","url":"http://www.idefense.com/application/poi/display?id=261&type=vulnerabilities"},{"name":"15697","refsource":"SECUNIA","url":"http://secunia.com/advisories/15697"},{"name":"13952","refsource":"BID","url":"http://www.securityfocus.com/bid/13952"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2005-0563","datePublished":"2005-06-14T04:00:00.000Z","dateReserved":"2005-02-26T00:00:00.000Z","dateUpdated":"2024-08-07T21:21:06.600Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-06-14 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*","matchCriteriaId":"B4F9C143-4734-4E5D-9281-F51513C5CAAF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"563","Ordinal":"1","Title":"CVE-2005-0563","CVE":"CVE-2005-0563","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"563","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL (\"jav&#X41sc&#0010;ript:\") in an IMG tag.","Type":"Description","Title":"CVE-2005-0563"},{"CveYear":"2005","CveId":"563","Ordinal":"2","NoteData":"2005-06-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"563","Ordinal":"3","NoteData":"2019-05-31","Type":"Other","Title":"Modified"}]}}}