CVE-2005-0420: Medium severity Microsoft Exchange Server vulnerability
Published Feb 15, 2005
·Updated
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.
Affected Software
2 affected components
Microsoft Exchange Server=2003-sp1
Microsoft Exchange Server=2003
Event History
Feb 15, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0420?
CVE-2005-0420 is considered a medium severity vulnerability due to its potential impact on user security.
2
How do I fix CVE-2005-0420?
To fix CVE-2005-0420, ensure that you apply the latest security updates from Microsoft for Exchange Server 2003.
3
What does CVE-2005-0420 affect?
CVE-2005-0420 specifically affects Microsoft Exchange Server 2003 and its Outlook Web Access (OWA) component.
4
Can CVE-2005-0420 be exploited remotely?
Yes, CVE-2005-0420 can be exploited remotely by attackers to redirect users.
5
What is the impact of CVE-2005-0420?
The impact of CVE-2005-0420 includes the potential for phishing attacks that redirect users to malicious login pages.