CVE-2007-0220
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Outlook Web Access (OWA) de Microsoft Exchange Server 2000 SP3, y 2003 SP1 y SP2 permite a atacantes remotos ejecutar secuencias de comandos de su elección, falsificar contenido u obtener información sensible mediante ciertas codificaciones UTF, anexos de correo electrónico basados en secuencias de comandos, implicando una "etiqueta de conjunto de caracteres UTF manejada incorrectamente".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-01-12 CVE Reserved
- 2007-05-08 CVE Published
- 2024-05-26 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/25183 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/124113 | Third Party Advisory | |
http://www.osvdb.org/34389 | Broken Link | |
http://www.securityfocus.com/bid/23806 | Third Party Advisory | |
http://www.securitytracker.com/id?1018015 | Third Party Advisory | |
http://www.us-cert.gov/cas/techalerts/TA07-128A.html | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33887 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026 | 2020-04-09 |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/archive/1/468871/100/200/threaded | 2020-04-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2000 Search vendor "Microsoft" for product "Exchange Server" and version "2000" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2003 Search vendor "Microsoft" for product "Exchange Server" and version "2003" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2003 Search vendor "Microsoft" for product "Exchange Server" and version "2003" | sp2 |
Affected
|