CVE-2006-1193
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 39.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 39.78% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/exchange server
- Source
- secure@microsoft.com
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046892.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/20634Patch, Third Party Advisory
- http://securitytracker.com/id?1016280Patch, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/138188Third Party Advisory, US Government Resource
- http://www.osvdb.org/26441Broken Link
- http://www.sec-consult.com/fileadmin/Advisories/20060613-0_owa_xss_noexploit.txtThird Party Advisory
- http://www.securityfocus.com/bid/18381Patch, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA06-164A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/2326Permissions Required
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-029Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25550Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1070Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1161Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1315Third Party Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046892.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/20634Patch, Third Party Advisory
- http://securitytracker.com/id?1016280Patch, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/138188Third Party Advisory, US Government Resource
- http://www.osvdb.org/26441Broken Link
- http://www.sec-consult.com/fileadmin/Advisories/20060613-0_owa_xss_noexploit.txtThird Party Advisory
- http://www.securityfocus.com/bid/18381Patch, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA06-164A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/2326Permissions Required
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-029Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25550Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1070Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1161Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1315Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.