Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.
References
Link | Resource |
---|---|
http://secunia.com/advisories/14144 | Exploit Third Party Advisory |
http://www.securityfocus.com/bid/12459 | Exploit Third Party Advisory VDB Entry |
http://seclists.org/lists/fulldisclosure/2005/Feb/0106.html | Mailing List Third Party Advisory |
http://www.vupen.com/english/advisories/2005/0105 | Permissions Required |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19225 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-04-26 21:00
Updated : 2020-04-09 06:53
NVD link : CVE-2005-0420
Mitre link : CVE-2005-0420
JSON object : View
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Products Affected
microsoft
- exchange_server