Unrated severityNVD Advisory· Published Apr 27, 2005· Updated Apr 16, 2026
CVE-2005-0420
CVE-2005-0420
Description
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.
Affected products
2cpe:2.3:a:microsoft:exchange_server:2003:-:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:microsoft:exchange_server:2003:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- secunia.com/advisories/14144nvdExploitThird Party Advisory
- www.securityfocus.com/bid/12459nvdExploitThird Party AdvisoryVDB Entry
- seclists.org/lists/fulldisclosure/2005/Feb/0106.htmlnvdMailing ListThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/19225nvdThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2005/0105nvdPermissions Required
News mentions
0No linked articles in our index yet.