First published: Thu Aug 12 2004(Updated: )
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =5.5-sp1 | |
Microsoft Exchange Server | =5.5-sp4 | |
Microsoft Exchange Server | =5.5-sp2 | |
Microsoft Exchange Server | =5.5-sp3 | |
Microsoft Exchange Server | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0203 is classified as a critical vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2004-0203, ensure that you have applied the latest patches or upgrades to Microsoft Exchange Server 5.5.
CVE-2004-0203 affects Microsoft Exchange Server 5.5 across various service packs including SP1, SP2, SP3, and SP4.
Yes, CVE-2004-0203 can be exploited remotely by attackers to inject malicious scripts through HTML emails.
The impacts of CVE-2004-0203 include the ability for attackers to spoof content and compromise user information through XSS vulnerabilities.