Microsoft OWA Server Embedded Script Execution Vulnerability
BID:3650
Info
Microsoft OWA Server Embedded Script Execution Vulnerability
| Bugtraq ID: | 3650 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2001 12:00AM |
| Updated: | Dec 06 2001 12:00AM |
| Credit: | Discovery credited to Lex Arquette of WhiteHat Security. |
| Vulnerable: |
Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft OWA Server Embedded Script Execution Vulnerability
Outlook Web Access is a component of Exchange Server that allows for users to access their mail using a web browser.
Outlook Web Access contains a vulnerability that may result in attacker-supplied script code executing within the context of the mail interface. The vulnerability is due to a failure to properly detect and filter obfuscated script code.
Successful exploitation may result in attacker supplied script code performing OWA actions as the victim.
Outlook Web Access is a component of Exchange Server that allows for users to access their mail using a web browser.
Outlook Web Access contains a vulnerability that may result in attacker-supplied script code executing within the context of the mail interface. The vulnerability is due to a failure to properly detect and filter obfuscated script code.
Successful exploitation may result in attacker supplied script code performing OWA actions as the victim.
Exploit / POC
Microsoft OWA Server Embedded Script Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft OWA Server Embedded Script Execution Vulnerability
Solution:
Microsoft has released a fix:
Microsoft Exchange Server 5.5 SP1
Microsoft Exchange Server 5.5 SP3
Microsoft Exchange Server 5.5 SP4
Microsoft Exchange Server 5.5 SP2
Microsoft Exchange Server 5.5
Solution:
Microsoft has released a fix:
Microsoft Exchange Server 5.5 SP1
-
Microsoft Q313576
Microsoft Bulletin MS01-057 notes that "for this patch to function properly, the Outlook Web Access (OWA) server on which the patch is installed must have Internet Explorer (IE) 5.0 or greater installed. If the patch is installed on a system with a version of IE older than 5.0, unexpected consequenc
http://download.microsoft.com/download/exch55/Patch/05.05.77.2655/NT45 /EN-US/Q313576engi386.EXE
Microsoft Exchange Server 5.5 SP3
-
Microsoft Q313576
Microsoft Bulletin MS01-057 notes that "for this patch to function properly, the Outlook Web Access (OWA) server on which the patch is installed must have Internet Explorer (IE) 5.0 or greater installed. If the patch is installed on a system with a version of IE older than 5.0, unexpected consequenc
http://download.microsoft.com/download/exch55/Patch/05.05.77.2655/NT45 /EN-US/Q313576engi386.EXE
Microsoft Exchange Server 5.5 SP4
-
Microsoft Q313576
Microsoft Bulletin MS01-057 notes that "for this patch to function properly, the Outlook Web Access (OWA) server on which the patch is installed must have Internet Explorer (IE) 5.0 or greater installed. If the patch is installed on a system with a version of IE older than 5.0, unexpected consequenc
http://download.microsoft.com/download/exch55/Patch/05.05.77.2655/NT45 /EN-US/Q313576engi386.EXE
Microsoft Exchange Server 5.5 SP2
-
Microsoft Q313576
Microsoft Bulletin MS01-057 notes that "for this patch to function properly, the Outlook Web Access (OWA) server on which the patch is installed must have Internet Explorer (IE) 5.0 or greater installed. If the patch is installed on a system with a version of IE older than 5.0, unexpected consequenc
http://download.microsoft.com/download/exch55/Patch/05.05.77.2655/NT45 /EN-US/Q313576engi386.EXE
Microsoft Exchange Server 5.5
-
Microsoft Q313576
Microsoft Bulletin MS01-057 notes that "for this patch to function properly, the Outlook Web Access (OWA) server on which the patch is installed must have Internet Explorer (IE) 5.0 or greater installed. If the patch is installed on a system with a version of IE older than 5.0, unexpected consequenc
http://download.microsoft.com/download/exch55/Patch/05.05.77.2655/NT45 /EN-US/Q313576engi386.EXE
References
Microsoft OWA Server Embedded Script Execution Vulnerability
References:
References:
- Microsoft Security Bulletin (MS01-057) (Microsoft)
- Microsoft Technet Security (Microsoft)