4.3
CVSSv2

CVE-2010-2091

Published: 27/05/2010 Updated: 09/04/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote malicious users to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft exchange_server 2007

Exploits

$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ "Microsoft Outlook Web Access (OWA) version 822540" OS: Windows Server 2003 Internet Explorer 7 $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ There is an information disclosure vulnerability in "Microsoft Outlook Web Access (OWA) version 822540" The issue is with the id parameter ...