Vulnerabilities > CVE-2008-1547 - Open Redirect vulnerability in Microsoft Exchange Server 2003

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
microsoft
CWE-601
exploit available

Summary

Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Fake the Source of Data
    An adversary provides data under a falsified identity. The purpose of using the falsified identity may be to prevent traceability of the provided data or it might be an attempt by the adversary to assume the rights granted to another identity. One of the simplest forms of this attack would be the creation of an email message with a modified "From" field in order to appear that the message was sent from someone other than the actual sender. Results of the attack vary depending on the details of the attack, but common results include privilege escalation, obfuscation of other attacks, and data corruption/manipulation.

Exploit-Db

descriptionMicrosoft Outlook Web Access for Exchange Server 2003 'redir.asp' URI Redirection Vulnerability. CVE-2008-1547. Remote exploit for windows platform
idEDB-ID:32489
last seen2016-02-03
modified2008-10-15
published2008-10-15
reporterMartin Suess
sourcehttps://www.exploit-db.com/download/32489/
titleMicrosoft Outlook Web Access for Exchange Server 2003 - 'redir.asp' URI Redirection Vulnerability

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 31765 CVE(CAN) ID: CVE-2008-1547 Microsoft Exchange Server是一款流行的邮件服务器,Outlook Web Access是Exchange中用于通过Web浏览器读取和发送邮件的工具。 Outlook Web Access的exchweb/bin/redir.asp页面存在重新定向漏洞,远程攻击者可以在邮件中发送特制的URL,如果用户已经登录的话,则点击该链接就会被立即重新定向到钓鱼网站;如果用户未登录,则点击后会显示登录页面,然后在成功认证后将用户重新定向到钓鱼网站。 Microsoft Outlook Web Access for Exchange 2003 Microsoft --------- 目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本: <a href=http://www.microsoft.com/technet/security/ target=_blank>http://www.microsoft.com/technet/security/</a>
idSSV:4445
last seen2017-11-19
modified2008-11-14
published2008-11-14
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-4445
titleMicrosoft Outlook Web Access redir.asp URI重新定向漏洞