Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1164
    posted: 05/09/08
  • NSM Daily Update #1164
    posted: 05/09/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1164
    posted: 05/09/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1155
    posted: 05/09/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 05/09/08
Microsoft Security Bulletins

August 2004


Prior Updates:


August 2004

Microsoft Security Bulletin MS04-026

Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting and Spoofing Attacks (842436)

Severity: Moderate
Vulnerabilities:
  • Cross-site and Spoofing Vulnerability - CAN-2004-0203
    This is a cross-site scripting and spoofing vulnerability. The cross-site scripting vulnerability could allow an attacker to convince a user to run a malicious script. If this malicious script is run, it would execute in the security context of the user. Attempts to exploit this vulnerability require user interaction. This vulnerability could allow an attacker access to any data on the Outlook Web Access server that was accessible to the individual user.