Microsoft Outlook Web Access 'no-store' HTTP Directive Information Disclosure Weakness
BID:29121
Info
Microsoft Outlook Web Access 'no-store' HTTP Directive Information Disclosure Weakness
| Bugtraq ID: | 29121 |
| Class: | Design Error |
| CVE: |
CVE-2008-2143 |
| Remote: | No |
| Local: | Yes |
| Published: | May 09 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Bill KNox |
| Vulnerable: |
Microsoft Outlook Web Access 0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Web Access 'no-store' HTTP Directive Information Disclosure Weakness
Microsoft Outlook Web Access is prone to a weakness that may allow sensitive information to be unintentionally stored on the local computer.
To exploit this issue, an attacker would need to exploit another vulnerability. Specifically, the attacker would need to be able to read the victim's cache.
Microsoft Outlook Web Access is prone to a weakness that may allow sensitive information to be unintentionally stored on the local computer.
To exploit this issue, an attacker would need to exploit another vulnerability. Specifically, the attacker would need to be able to read the victim's cache.
Exploit / POC
Microsoft Outlook Web Access 'no-store' HTTP Directive Information Disclosure Weakness
To exploit this issue, an attacker would need access to the victim's browser cache.
To exploit this issue, an attacker would need access to the victim's browser cache.
Solution / Fix
Microsoft Outlook Web Access 'no-store' HTTP Directive Information Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Outlook Web Access 'no-store' HTTP Directive Information Disclosure Weakness
References:
References:
- Outlook Web Access Homepage (Microsoft)
- Vulnerability Note VU#829876 (US-CERT)