SMTP: Microsoft Outlook Web Access for Exchange Server HTML Validating Cross Site Scripting

This signature detects attempts to exploit a known vulnerability in Microsoft Outlook Web Access for Exchange Server. A successful cross site scripting attack could lead to arbitrary code execution.

Extended Description

Microsoft Outlook Web Access (OWA) for Exchange Server is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal potentially sensitive information and launch other attacks.

Affected Products

Avaya messaging_application_server,Microsoft exchange_server_2003

References

BugTraq: 30130

CVE: CVE-2008-2247

Short Name
SMTP:HTML-VAL-XSS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SMTP
Keywords
Access CVE-2008-2247 CVE-2008-2248 Cross Exchange HTML Microsoft Outlook Scripting Server Site Validating Web bid:30130 for
Release Date
10/11/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Avaya

Microsoft

CVSS Score

4.3

Found a potential security threat?