Неправильная нейтрализация ввода во время создания веб-страницы («межсайтовый сценарий») в Microsoft Exchange Server позволяет несанкционированному злоумышленнику выполнить подмену в сети.
Показать оригинальное описание (EN)
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 40
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
|
— | — |
|
Microsoft Exchange_Server_Subscription_Edition
cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:*
|
— |
15.02.2562.043
|