Main > System > OS Enhancements >

Microsoft Security Bulletin MS03-047 828489

Microsoft Security Bulletin MS03-047 828489

Sponsored Links

Microsoft Security Bulletin MS03-047 828489 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 1.8M
Platform: Windows XP, Windows 2000, Windows 98
License: Update
Price: $1.00
Downloads: 364
Date added: 2008-10-24
Publisher: Microsoft

Microsoft Security Bulletin MS03-047 828489 description

A cross-site scripting (XSS) vulnerability results due to the way that Outlook Web Access (OWA) performs HTML encoding in the Compose New Message form.

An attacker could seek to exploit this vulnerability by having a user run script on the attackers behalf. The script would execute in the security context of the user. If the script executes in the security context of the user, the attackers code could then execute by using the security settings of the OWA Web site (or of a Web site that is hosted on the same server as the OWA Web site) and could enable the attacker to access any data belonging to the site where the user has access.

To exploit this vulnerability through OWA, an attacker would have to send an e-mail message that has a specially-formed link to the user. The user would then have to click the link. To exploit this vulnerability in another way, an attacker would have to know the name of the users Exchange server and then entice the user to open a specially-formed link from another source while the user is logged on to OWA.

Note: Customers who have customized any of the ASP pages in the File Information section in this document should backup those files before applying this patch as they will be overwritten when the patch is applied. Any customizations would then need to be reapplied to the new ASP pages. Please refer to the Microsoft Support Policy for the Customization of Outlook Web Access available at http://support.microsoft.com/default.aspx?scid=kb;en-us;327178

Microsoft Security Bulletin MS03-047 828489 Screenshot

Advertisements

Microsoft Security Bulletin MS03-047 828489 Keywords

Bookmark Microsoft Security Bulletin MS03-047 828489

Hyperlink code:
Link for forum:

Microsoft Security Bulletin MS03-047 828489 Copyright

WareSeeker periodically updates pricing and software information of Microsoft Security Bulletin MS03-047 828489 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of Microsoft Security Bulletin MS03-047 828489 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
Buffer Overrun in Could Allow Code Execution Free Download
Vulnerability Could Allow Remote Code Execution Free Download
Unchecked Buffer in ASP.NET Worker Process Free Download
Privilege elevation flaw in Network Connection Manager Free Download
Unchecked Buffer in Windows Redirector Free Download
Microsoft Security Bulletin MS07-002 is a useful program which can substitute a prior security update. Free Download