The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS01-057: Specially Formed Script in HMTL Mail can Execute in Exchange 5.5 OWA
Time: 18:57 EST/23:57 GMT | News Source: Microsoft TechNet Security | Posted By: Matthew Sabean

Outlook Web Access (OWA) is a service of Exchange 5.5 Server that allows users to access and manipulate messages in their Exchange mailbox by using a web browser. A flaw exists in the way OWA handles inline script in messages in conjunction with Internet Explorer (IE). If an HTML message that contains specially formatted script is opened in OWA, the script executes when the message is opened. Because OWA requires that scripting be enabled in the zone where the OWA server is located, a vulnerability results because this script could take any action against the user's Exchange mailbox that the user himself was capable of, including sending, moving, or deleting messages. An attacker could maliciously exploit this flaw by sending a specially crafted message to the user. If the user opened the message in OWA, the script would then execute. While it is possible for a script to send a message as the user, it is impossible for the script to send a message to addresses in the user's address book. Thus, the flaw cannot be exploited for mass-mailing attacks. Also, mounting a successful attack requires knowledge of the intended victim's choice of mail clients and reading habits. If the maliciously crafted message were read in any mail client other than a browser through OWA, the attack would fail.

Download locations for this patch:
Microsoft Exchange 5.5: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=34402

Write Comment
Return to News

  Displaying 301 through 307 of 307
Prev | First
  The time now is 4:55:26 PM ET.
Any comment problems? E-mail us
#301 By 4240821 (77.246.244.253) at 11/21/2024 8:49:08 AM
https://justpaste.me/BqdF1
https://justpaste.me/Cc2K3
https://justpaste.me/CLt0
https://justpaste.me/CbhU4
https://justpaste.me/Ce0g1
https://justpaste.me/CQC0
https://justpaste.me/CQXv2
https://justpaste.me/CcmD2
https://justpaste.me/C3s0
https://justpaste.me/CeLo4

#302 By 4240821 (77.246.244.253) at 11/21/2024 2:56:26 PM
https://www.google.dk/amp/s/sexonly.su/get/a87/a87jhnkridflkaiqsz.php
https://www.google.de/amp/s/sluts.su/get/a155/a155fhnswgpoluauqrw.php
https://www.google.fi/amp/s/sexonly.top/get/a22/a22bojtjwovdxdwaie.php
https://www.google.dz/amp/s/sexonly.su/get/a6/a6qvfcjrktaucpsbx.php
https://www.google.fi/amp/s/sexonly.top/get/a26/a26vjzkyvcvnqhacvg.php
https://www.google.dm/amp/s/sexonly.top/get/a126/a126epsdlphdqhgviak.php
https://www.google.dj/amp/s/nsfw.su/get/a226/a226ioneogfvtpdfwth.php
https://www.google.es/amp/s/sluts.su/get/a115/a115upelbjtwaivwtra.php
https://www.google.ec/amp/s/nsfw.su/get/a199/a199pngclslaxmeqcin.php
https://www.google.cz/amp/s/nsfw.su/get/a189/a189yuxfmvhwkunwgfx.php

#303 By 4240821 (80.73.244.53) at 11/22/2024 12:45:50 AM
https://www.google.cd/amp/s/sexonly.top/get/a103/a103tywwqzkpuaavrru.php
https://www.google.cg/amp/s/sexonly.top/get/a204/a204foodnhnxskubvbe.php
https://www.google.ci/amp/s/lustful.su/get/a294/a294lixqqqgasenzwcp.php
https://www.google.cg/amp/s/sluts.su/get/a241/a241signvjmjabpdbby.php
https://www.google.ch/amp/s/lustful.su/get/a79/a79hwrixicsiejqrtw.php
https://www.google.cl/amp/s/sexonly.su/get/a59/a59nimhwdbvoiepugv.php
https://www.google.cf/amp/s/sexonly.su/get/a258/a258dcnjbkaorwddxby.php
https://www.google.cd/amp/s/sexonly.su/get/a43/a43xxdxjwyxzgqtyvr.php
https://www.google.ch/amp/s/sexonly.su/get/a29/a29pzrapcghdjkjqsj.php
https://www.google.cm/amp/s/sexonly.top/get/a257/a257tvckgdlnjppqryo.php

#304 By 4240821 (166.1.149.158) at 11/22/2024 12:59:31 PM
https://www.google.gp/amp/s/lustful.su/get/a63/a63bztanymtezgpost.php
https://www.google.fr/amp/s/sexonly.su/get/a157/a157phkeaekluekmmxz.php
https://www.google.gp/amp/s/sluts.su/get/a50/a50mgjquddbsrllcwg.php
https://www.google.ga/amp/s/sexonly.su/get/a291/a291vrkyivjsiceagwv.php
https://www.google.gm/amp/s/sluts.su/get/a243/a243aqsildsjlvotlxr.php
https://www.google.gl/amp/s/sluts.su/get/a161/a161qayiqajsxnprxpl.php
https://www.google.gr/amp/s/nsfw.su/get/a287/a287buyfnvopnifaerv.php
https://www.google.gm/amp/s/lustful.su/get/a119/a119pluynivovlpymcj.php
https://www.google.fr/amp/s/sexonly.top/get/a22/a22rjtauygxzpurgct.php
https://www.google.ga/amp/s/lustful.su/get/a121/a121lhaqsjthnjdmpav.php

#305 By 4240821 (166.1.149.158) at 11/22/2024 1:39:38 PM
https://www.google.im/amp/s/sluts.su/get/a94/a94mdbdlnnktnimkdt.php
https://www.google.ie/amp/s/lustful.su/get/a146/a146dfjzsvjnuigdglh.php
https://www.google.hu/amp/s/sexonly.top/get/a84/a84wfyszrrsgizjnrh.php
https://www.google.is/amp/s/nsfw.su/get/a139/a139mmzrndligriqngz.php
https://www.google.iq/amp/s/sexonly.top/get/a280/a280uythlxawfmjivsr.php
https://www.google.hn/amp/s/sluts.su/get/a237/a237uhbjizwjnmaoaqw.php
https://www.google.iq/amp/s/sluts.su/get/a135/a135xucjwvnplnfmyyh.php
https://www.google.ie/amp/s/sexonly.su/get/a283/a283nyhgfbkdwzjnkgz.php
https://www.google.hu/amp/s/sexonly.top/get/a130/a130jtegdqaanybblzt.php
https://www.google.it/amp/s/lustful.su/get/a260/a260mcadazdmqgudvyt.php

#306 By 4240821 (45.88.102.114) at 11/23/2024 2:51:52 AM
https://justpaste.me/BuEW2
https://justpaste.me/Bdqk3
https://justpaste.me/CWcJ2
https://justpaste.me/C9eS1
https://justpaste.me/BjiY3
https://justpaste.me/C8lF1
https://justpaste.me/CGJa1
https://justpaste.me/Bf4s
https://justpaste.me/Cg731
https://justpaste.me/CBD71

#307 By 4240821 (62.76.153.72) at 11/23/2024 2:16:32 PM
https://justpaste.me/Bhri1
https://justpaste.me/CdU15
https://justpaste.me/Cca11
https://justpaste.me/C1qz1
https://justpaste.me/BgTv3
https://justpaste.me/CZtF2
https://justpaste.me/CJWD5
https://justpaste.me/Bb6H2
https://justpaste.me/BxOy4
https://justpaste.me/C7bB1

Write Comment
Return to News
  Displaying 301 through 307 of 307
Prev | First
  The time now is 4:55:26 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *