|
Microsoft Exchange Server 5.5 Outlook Web Access Cross-Site Scripting Vulnerability
It has been reported that Microsoft Exchange Server Outlook Web Access is prone to a cross-site scripting vulnerability. The issue is reported to exist due insufficient sanitization of user-supplied data in HTML encoding performed by Compose New Message form. The problem may allow a remote attacker to execute HTML or script code in the browser of a user running the vulnerable software. Successful exploitation of this attack may allow an attacker to steal cookie-based authentication information that could be used to launch further attacks. |
|
|
Privacy Statement |