Unrated severityNVD Advisory· Published Nov 23, 2004· Updated Apr 16, 2026
CVE-2004-0203
CVE-2004-0203
Description
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.
Affected products
5cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-026nvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/948750nvdThird Party AdvisoryUS Government Resource
- exchange.xforce.ibmcloud.com/vulnerabilities/16583nvdThird Party AdvisoryVDB Entry
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2016nvdThird Party Advisory
News mentions
0No linked articles in our index yet.