Vulnerability Name:

CVE-2006-1193 (CCN-25550)

Assigned:2006-06-13
Published:2006-06-13
Updated:2020-04-09
Summary:Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
CVSS v3 Severity:4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-Disclosure Mailing List, Wed Jun 14 2006 - 02:03:54 CDT
SEC Consult SA-20060613-0 :: Outlook Web Access Cross Site Scripting Vulnerability

Source: MITRE
Type: CNA
CVE-2006-1193

Source: FULLDISC
Type: Mailing List, Third Party Advisory
20060614 SEC Consult SA-20060613-0 :: Outlook Web Access Cross Site Scripting Vulnerability

Source: CCN
Type: SA20634
Microsoft Exchange Server Outlook Web Access Script Insertion

Source: SECUNIA
Type: Patch, Third Party Advisory
20634

Source: CCN
Type: SECTRACK ID: 1016280
Microsoft Outlook Web Access Input Validation Hole Permits Cross-Site Scripting Attacks

Source: SECTRACK
Type: Patch, Third Party Advisory, VDB Entry
1016280

Source: CCN
Type: ASA-2006-126
Windows Security Updates for June 2006 - (MS06-021 - MS06-032)

Source: CCN
Type: NORTEL BULLETIN ID: 2008008958, Rev 1
Centrex IP Client Manager (CICM) response to Microsoft July security bulletin

Source: CCN
Type: US-CERT VU#138188
Microsoft Outlook Web Access for Exchange Server script injection vulnerability

Source: CERT-VN
Type: Third Party Advisory, US Government Resource
VU#138188

Source: CCN
Type: Microsoft Security Bulletin MS06-029
Vulnerability in Microsoft Exchange Server Running Outlook Web Access Could Allow Script Injection (912442)

Source: CCN
Type: Microsoft Security Bulletin MS07-026
Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (931832)

Source: CCN
Type: Microsoft Security Bulletin MS08-039
Vulnerabilities in Outlook Web Access for Exchange Server Could Allow Elevation of Privilege (953747)

Source: CCN
Type: Microsoft Security Bulletin MS09-003
Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)

Source: OSVDB
Type: Broken Link
26441

Source: CCN
Type: OSVDB ID: 26441
Microsoft Exchange Server Outlook Web Access HTML Parsing Unspecified XSS

Source: MISC
Type: Third Party Advisory
http://www.sec-consult.com/fileadmin/Advisories/20060613-0_owa_xss_noexploit.txt

Source: BID
Type: Patch, Third Party Advisory, VDB Entry
18381

Source: CCN
Type: BID-18381
Microsoft Exchange Server Outlook Web Access Script Injection Vulnerability

Source: CERT
Type: Third Party Advisory, US Government Resource
TA06-164A

Source: VUPEN
Type: Permissions Required
ADV-2006-2326

Source: MS
Type: Patch, Vendor Advisory
MS06-029

Source: XF
Type: Third Party Advisory, VDB Entry
exchange-owa-xss(25550)

Source: XF
Type: UNKNOWN
exchange-owa-xss(25550)

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:1070

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:1161

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:1315

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:exchange_server:2000:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2000:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:1070
    V
    Exchange Server 2003,SP2 when running Outlook Web Access Vulnerability
    2014-06-30
    oval:org.mitre.oval:def:1161
    V
    Exchange Server 2003,SP1 when running Outlook Web Access Vulnerability
    2014-06-30
    oval:org.mitre.oval:def:1315
    V
    Exchange Server 2000 when running Outlook Web Access Vulnerability
    2014-06-30
    BACK
    microsoft exchange server 2000 sp1
    microsoft exchange server 2000 sp2
    microsoft exchange server 2000 sp3
    microsoft exchange server 2003 sp1
    microsoft exchange server 2000 sp3
    microsoft exchange server 2003 sp2