CVE-2007-0220

Microsoft Exchange Server 2000 SP3, 2003 SP1-SP2 - Cross-Site Scripting via UTF-Encoded Email Attachments

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".

References (11)

Core 11
Core References
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1711
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/468871/100/200/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018015
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/124113
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23806
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25183
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-128A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33887
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/34389

Scores

EPSS 0.3315
EPSS Percentile 98.2%

Details

CWE
CWE-79
Status published
Products (2)
microsoft/exchange_server 2000 sp3
microsoft/exchange_server 2003 sp1 (2 CPE variants)
Published May 08, 2007
Tracked Since Feb 18, 2026