Unrated severityNVD Advisory· Published May 8, 2007· Updated Apr 23, 2026
CVE-2007-0220
CVE-2007-0220
Description
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
Affected products
3cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026nvdPatch
- secunia.com/advisories/25183nvdThird Party Advisory
- www.kb.cert.org/vuls/id/124113nvdThird Party AdvisoryUS Government Resource
- www.securityfocus.com/archive/1/468871/100/200/threadednvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/23806nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.us-cert.gov/cas/techalerts/TA07-128A.htmlnvdThird Party AdvisoryUS Government Resource
- exchange.xforce.ibmcloud.com/vulnerabilities/33887nvdThird Party AdvisoryVDB Entry
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371nvdThird Party Advisory
- www.osvdb.org/34389nvdBroken Link
- www.vupen.com/english/advisories/2007/1711nvdPermissions Required
News mentions
0No linked articles in our index yet.