Microsoft Outlook Web Access HTML Attachment Script Execution Vulnerability
BID:8113
Info
Microsoft Outlook Web Access HTML Attachment Script Execution Vulnerability
| Bugtraq ID: | 8113 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2003 12:00AM |
| Updated: | Jul 05 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Hugo Vázquez Caramés & Toni Cortés Martínez. |
| Vulnerable: |
Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Web Access HTML Attachment Script Execution Vulnerability
OWA contains a vulnerability that may result in attacker-supplied script code executing within the context of the mail interface when processing e-mail containing HTML message attachments.
It is possible to prevent filtering of the attachment by omitting a certain URI parameter from a generated URL.
If did parameter does not exist, no filtering will be performed. Unfiltered, the script code will execute if embedded in an HTML email opened by a user.
OWA contains a vulnerability that may result in attacker-supplied script code executing within the context of the mail interface when processing e-mail containing HTML message attachments.
It is possible to prevent filtering of the attachment by omitting a certain URI parameter from a generated URL.
If did parameter does not exist, no filtering will be performed. Unfiltered, the script code will execute if embedded in an HTML email opened by a user.
Exploit / POC
Microsoft Outlook Web Access HTML Attachment Script Execution Vulnerability
A proof of concept exploit is available:
A proof of concept exploit is available:
Solution / Fix
Microsoft Outlook Web Access HTML Attachment Script Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Outlook Web Access HTML Attachment Script Execution Vulnerability
References:
References:
- Microsoft User Domain Credentials access via OWA XSS (InfoHacking)
- XSS in OWA allows stealing windows domain user credentials (Hugo "Vázquez" "Caramés"
)