Back

CVE-2004-0203

Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.

Published: Nov 23, 2004 Modified: Jun 16, 2026
CWE-79

CVSS Metrics

Affected Products (5)

Vendor Product Version
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft exchange_server 5.5
microsoft exchange_server 5.5

GitHub Security Advisory GHSA-8ghp-mgj8-vqhc

Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 20.98%

Top 3% most likely to be exploited

Threat Score 23.5 / 100

Data Sources

NVD EPSS GitHub