CVE-2010-2091
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 17.94% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/exchange server
- Source
- cve@mitre.org
References
- http://www.exploit-db.com/exploits/12728Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/511401/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/511416/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/511448/100/0/threadedThird Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58835VDB Entry
- http://www.exploit-db.com/exploits/12728Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/511401/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/511416/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/511448/100/0/threadedThird Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58835VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.