CVE-2006-1193

Microsoft Exchange Server 2000 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Daniel Fabian · perlremotewindows
https://www.exploit-db.com/exploits/28005

Scores

EPSS 0.5892
EPSS Percentile 98.2%

Classification

CWE
CWE-79
Status draft

Affected Products (3)

microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server

Timeline

Published Jun 13, 2006
Tracked Since Feb 18, 2026