CVE-2007-0220

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
References
Link Resource
http://secunia.com/advisories/25183 Third Party Advisory
http://www.kb.cert.org/vuls/id/124113 Third Party Advisory US Government Resource
http://www.osvdb.org/34389 Broken Link
http://www.securityfocus.com/archive/1/468871/100/200/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/468871/100/200/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/23806 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1018015 Third Party Advisory VDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-128A.html Third Party Advisory US Government Resource
http://www.vupen.com/english/advisories/2007/1711 Permissions Required
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/33887 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371 Third Party Advisory
http://secunia.com/advisories/25183 Third Party Advisory
http://www.kb.cert.org/vuls/id/124113 Third Party Advisory US Government Resource
http://www.osvdb.org/34389 Broken Link
http://www.securityfocus.com/archive/1/468871/100/200/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/468871/100/200/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/23806 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1018015 Third Party Advisory VDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-128A.html Third Party Advisory US Government Resource
http://www.vupen.com/english/advisories/2007/1711 Permissions Required
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/33887 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*

History

21 Nov 2024, 00:25

Type Values Removed Values Added
References () http://secunia.com/advisories/25183 - Third Party Advisory () http://secunia.com/advisories/25183 - Third Party Advisory
References () http://www.kb.cert.org/vuls/id/124113 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/124113 - Third Party Advisory, US Government Resource
References () http://www.osvdb.org/34389 - Broken Link () http://www.osvdb.org/34389 - Broken Link
References () http://www.securityfocus.com/archive/1/468871/100/200/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/468871/100/200/threaded - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/23806 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/23806 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id?1018015 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id?1018015 - Third Party Advisory, VDB Entry
References () http://www.us-cert.gov/cas/techalerts/TA07-128A.html - Third Party Advisory, US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-128A.html - Third Party Advisory, US Government Resource
References () http://www.vupen.com/english/advisories/2007/1711 - Permissions Required () http://www.vupen.com/english/advisories/2007/1711 - Permissions Required
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026 - Patch () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/33887 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/33887 - Third Party Advisory, VDB Entry
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371 - Third Party Advisory () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371 - Third Party Advisory

Information

Published : 2007-05-08 23:19

Updated : 2024-11-21 00:25


NVD link : CVE-2007-0220

Mitre link : CVE-2007-0220

CVE.ORG link : CVE-2007-0220


JSON object : View

Products Affected

microsoft

  • exchange_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')