CVE-2010-2091
medium · 4.3Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
4.3
CVSS
17.9%
EPSS (exploit prob.)
97th
EPSS percentile
2010-05-27
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | exchange_server | 2007 |
| microsoft | internet_explorer | 7 |
| microsoft | windows_server_2003 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.exploit-db.com/exploits/12728
- http://www.securityfocus.com/archive/1/511401/100/0/threaded
- http://www.securityfocus.com/archive/1/511416/100/0/threaded
- http://www.securityfocus.com/archive/1/511448/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58835
- http://www.exploit-db.com/exploits/12728
- http://www.securityfocus.com/archive/1/511401/100/0/threaded
- http://www.securityfocus.com/archive/1/511416/100/0/threaded
- http://www.securityfocus.com/archive/1/511448/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58835
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-2091