Microsoft Exchange Server Outlook Web Access HTML Injection Vulnerability

Bugtraq ID: 13952
Class: Input Validation Error
CVE: CVE-2005-0563
Remote: Yes
Local: No
Published: Jun 14 2005 12:00AM
Updated: Jul 12 2009 02:56PM
Credit: Gael Delalleau is credited with discovery.
Vulnerable: Microsoft Outlook Web Access for Exchange Server 5.5
+ Microsoft Exchange Server 5.5 SP4
+ Microsoft Exchange Server 5.5 SP3
+ Microsoft Exchange Server 5.5 SP2
+ Microsoft Exchange Server 5.5 SP1
+ Microsoft Exchange Server 5.5
Microsoft Exchange Server 5.5 SP4
- Microsoft BackOffice 4.5
- Microsoft BackOffice 4.5
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Professional
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6
- Microsoft Windows NT 4.0 SP6
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0
Not Vulnerable: Microsoft Outlook Web Access for Exchange Server 2003
+ Microsoft Exchange Server 2003 SP1
+ Microsoft Exchange Server 2003
Microsoft Outlook Web Access for Exchange 2000 Server
+ Microsoft Exchange Server 2000 SP3
+ Microsoft Exchange Server 2000 SP2
+ Microsoft Exchange Server 2000 SP1
+ Microsoft Exchange Server 2000
Microsoft Exchange Server 2003 SP1
Microsoft Exchange Server 2003
Microsoft Exchange Server 2000 SP3


 

Privacy Statement
Copyright 2010, SecurityFocus