CVE-2003-0712

Microsoft Exchange Server 5.5 OWA - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.

References (5)

Core 5
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.cert.org/advisories/CA-2003-27.html
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=106631918405915&w=2
Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/8832
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/435444
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-047

Scores

EPSS 0.1736
EPSS Percentile 96.8%

Details

CWE
CWE-79
Status published
Products (1)
microsoft/exchange_server 5.5 (5 CPE variants)
Published Nov 17, 2003
Tracked Since Feb 18, 2026