CVE-2001-0726

Microsoft Exchange Server 5.5 - Cross-Site Scripting via HTML Email in Outlook Web Access

Title source: llm
STIX 2.1

Description

Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7663
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/5557
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3650

Scores

EPSS 0.1612
EPSS Percentile 96.6%

Details

Status published
Products (1)
microsoft/exchange_server 5.5
Published Dec 06, 2001
Tracked Since Feb 18, 2026