Back

CVE-2005-0563

Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("jav&#X41sc
ript:") in an IMG tag.

Published: Jun 14, 2005 Modified: Jun 16, 2026
CWE-79

CVSS Metrics

Affected Products (1)

Vendor Product Version
microsoft exchange_server 5.5

GitHub Security Advisory GHSA-3gv6-jr8r-hr5r

Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 14.22%

Top 4% most likely to be exploited

Threat Score 21.5 / 100

Data Sources

NVD EPSS GitHub