Back
CVE-2004-0203
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.
Published: Nov 23, 2004
Modified: Jun 16, 2026
CWE-79
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| microsoft | exchange_server | 5.5 |
| microsoft | exchange_server | 5.5 |
| microsoft | exchange_server | 5.5 |
| microsoft | exchange_server | 5.5 |
| microsoft | exchange_server | 5.5 |
GitHub Security Advisory GHSA-8ghp-mgj8-vqhc
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service...
References (8)
- http://www.kb.cert.org/vuls/id/948750 Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-026 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16583 Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2016 Third Party Advisory
- http://www.kb.cert.org/vuls/id/948750 Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-026 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16583 Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2016 Third Party Advisory
Risk Scores
CVSS Score
4.3 / 10
EPSS Score
20.98%
Top 3% most likely to be exploited
Threat Score
23.5 / 100
Data Sources
NVD
EPSS
GitHub