Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Exchange Server 5.5 Outlook Web Access Cross-Site Scripting Vulnerability

It has been reported that Microsoft Exchange Server Outlook Web Access is prone to a cross-site scripting vulnerability. The issue is reported to exist due insufficient sanitization of user-supplied data in HTML encoding performed by Compose New Message form. The problem may allow a remote attacker to execute HTML or script code in the browser of a user running the vulnerable software.

Successful exploitation of this attack may allow an attacker to steal cookie-based authentication information that could be used to launch further attacks.







 

Privacy Statement
Copyright 2008, SecurityFocus