CVE-2003-0712: XSS
Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0712?
CVE-2003-0712 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts.
How do I fix CVE-2003-0712?
To fix CVE-2003-0712, it is recommended to apply the latest service pack or patches provided by Microsoft for Exchange Server 5.5.
Which versions of Microsoft Exchange Server are affected by CVE-2003-0712?
CVE-2003-0712 affects Microsoft Exchange Server 5.5 versions including SP1, SP2, SP3, and SP4.
What type of attack is facilitated by CVE-2003-0712?
CVE-2003-0712 facilitates Cross-Site Scripting (XSS) attacks, allowing malicious scripts to be executed in the context of a user’s session.
Is user input related to CVE-2003-0712?
Yes, CVE-2003-0712 is related to inadequate HTML encoding of user input in the Compose New Message form in OWA.