Microsoft Exchange Server Outlook Web Access HTML Injection Vulnerability
BID:13952
Info
Microsoft Exchange Server Outlook Web Access HTML Injection Vulnerability
| Bugtraq ID: | 13952 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-0563 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2005 12:00AM |
| Updated: | May 31 2019 10:00PM |
| Credit: | Gael Delalleau is credited with discovery. |
| Vulnerable: |
Microsoft Outlook Web Access for Exchange Server 5.5 Microsoft Exchange Server 5.5 SP4 |
| Not Vulnerable: |
Microsoft Outlook Web Access for Exchange Server 2003 Microsoft Outlook Web Access for Exchange 2000 Server Microsoft Exchange Server 2003 SP1 Microsoft Exchange Server 2003 Microsoft Exchange Server 2000 SP3 |
Discussion
Microsoft Exchange Server Outlook Web Access HTML Injection Vulnerability
Outlook Web Access is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the affected application of an unsuspecting user in the context of the affected user.
This issue is reported to affect Outlook Web Access for Exchange Server 5.5.
Outlook Web Access is prone to an HTML injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the affected application of an unsuspecting user in the context of the affected user.
This issue is reported to affect Outlook Web Access for Exchange Server 5.5.
Exploit / POC
Microsoft Exchange Server Outlook Web Access HTML Injection Vulnerability
No exploit required.
No exploit required.
Solution / Fix
Microsoft Exchange Server Outlook Web Access HTML Injection Vulnerability
Solution:
Microsoft has released fixes to address supported versions of the software.
Microsoft Exchange Server 5.5 SP4
Solution:
Microsoft has released fixes to address supported versions of the software.
Microsoft Exchange Server 5.5 SP4
-
Microsoft Security Update for Exchange 5.5 Server (KB895179)
http://www.microsoft.com/downloads/details.aspx?familyid=08435B77-9F3A -40F5-B13A-A7019CB1C244&displaylang=en
References
Microsoft Exchange Server Outlook Web Access HTML Injection Vulnerability
References:
References:
- ADVISORY 06.14.05 : Microsoft Outlook Web Access Cross-Site Scripting Vulnerabil (iDEFENSE)
- Exchange Server Home Page (Microsoft)
- Microsoft Security Bulletin MS05-029 (Microsoft)