CVE-2001-0726
Microsoft Exchange Server 5.5 - Cross-Site Scripting via HTML Email in Outlook Web Access
Title source: llmDescription
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7663
Patch, Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057
Broken Link vdb-entry
x_refsource_osvdb
http://www.osvdb.org/5557
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/3650
Scores
EPSS
0.1612
EPSS Percentile
96.6%
Details
Status
published
Products (1)
microsoft/exchange_server
5.5
Published
Dec 06, 2001
Tracked Since
Feb 18, 2026