CVE-2005-0563
Microsoft Exchange Server - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("javAsc
ript:") in an IMG tag.
References (4)
Scores
EPSS
0.2296
EPSS Percentile
95.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
microsoft/exchange_server
Timeline
Published
Jun 14, 2005
Tracked Since
Feb 18, 2026