CERT-In Vulnerability Note
CIVN-2005-0052
Vulnerability in Outlook Web Access for Exchange Server 5.5 Could Allow Cross-Site Scripting Attacks
Original Issue Date:June 15, 2005
Severity Rating: MEDIUM
Systems Affected
Microsoft Exchange Server 5.5 Service Pack 4.
Overview
Outlook Web Access OWA is prone to an HTML injection vulnerability. This is due to a failure in the application to properly sanitize user-supplied input.
Description
This is a cross-site scripting vulnerability that could allow an attacker to convince a user to run a malicious script.
If this malicious script is run, it would execute in the security context of the user. Attempts to exploit this vulnerability require user interaction.The script could take any action on the users computer that the Web site is authorized to take; this could include monitoring the Web session and forwarding information to a third party, running other code on the users system and reading or writing cookies.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS05-029
Vendor Information
Microsoft Corporation
http://www.microsoft.com/technet/security/bulletin/MS05-029.mspx
References
Microsoft Security Bulletin
http://www.microsoft.com/technet/security/bulletin/MS05-029.mspx
US CERT Vulnerability Note VU#300373
http://www.kb.cert.org/vuls/id/300373
Security Focus bugtraq id 13952
http://www.securityfocus.com/bid/13952
Secunia Advisory SA15697
http://secunia.com/advisories/15697
iDEFENSE Security Advisory
http://www.idefense.com/application/poi/display?id=261&type=vulnerabilities&flashstatus=true
CVE Name
CAN-2005-0563
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|