Vulnerability Name: | CVE-2006-1193 (CCN-25550) | ||||||||||||||||
Assigned: | 2006-06-13 | ||||||||||||||||
Published: | 2006-06-13 | ||||||||||||||||
Updated: | 2020-04-09 | ||||||||||||||||
Summary: | Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing." | ||||||||||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Wed Jun 14 2006 - 02:03:54 CDT SEC Consult SA-20060613-0 :: Outlook Web Access Cross Site Scripting Vulnerability Source: MITRE Type: CNA CVE-2006-1193 Source: FULLDISC Type: Mailing List, Third Party Advisory 20060614 SEC Consult SA-20060613-0 :: Outlook Web Access Cross Site Scripting Vulnerability Source: CCN Type: SA20634 Microsoft Exchange Server Outlook Web Access Script Insertion Source: SECUNIA Type: Patch, Third Party Advisory 20634 Source: CCN Type: SECTRACK ID: 1016280 Microsoft Outlook Web Access Input Validation Hole Permits Cross-Site Scripting Attacks Source: SECTRACK Type: Patch, Third Party Advisory, VDB Entry 1016280 Source: CCN Type: ASA-2006-126 Windows Security Updates for June 2006 - (MS06-021 - MS06-032) Source: CCN Type: NORTEL BULLETIN ID: 2008008958, Rev 1 Centrex IP Client Manager (CICM) response to Microsoft July security bulletin Source: CCN Type: US-CERT VU#138188 Microsoft Outlook Web Access for Exchange Server script injection vulnerability Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#138188 Source: CCN Type: Microsoft Security Bulletin MS06-029 Vulnerability in Microsoft Exchange Server Running Outlook Web Access Could Allow Script Injection (912442) Source: CCN Type: Microsoft Security Bulletin MS07-026 Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (931832) Source: CCN Type: Microsoft Security Bulletin MS08-039 Vulnerabilities in Outlook Web Access for Exchange Server Could Allow Elevation of Privilege (953747) Source: CCN Type: Microsoft Security Bulletin MS09-003 Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239) Source: OSVDB Type: Broken Link 26441 Source: CCN Type: OSVDB ID: 26441 Microsoft Exchange Server Outlook Web Access HTML Parsing Unspecified XSS Source: MISC Type: Third Party Advisory http://www.sec-consult.com/fileadmin/Advisories/20060613-0_owa_xss_noexploit.txt Source: BID Type: Patch, Third Party Advisory, VDB Entry 18381 Source: CCN Type: BID-18381 Microsoft Exchange Server Outlook Web Access Script Injection Vulnerability Source: CERT Type: Third Party Advisory, US Government Resource TA06-164A Source: VUPEN Type: Permissions Required ADV-2006-2326 Source: MS Type: Patch, Vendor Advisory MS06-029 Source: XF Type: Third Party Advisory, VDB Entry exchange-owa-xss(25550) Source: XF Type: UNKNOWN exchange-owa-xss(25550) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:1070 Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:1161 Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:1315 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |