CVE-2006-1193 describes a cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, specifically impacting Outlook Web Access (OWA) due to HTML parsing issues. An attacker could inject arbitrary HTML or web script, requiring user assistance for successful exploitation. While the CVSS score is low (2.6), indicating a network attack vector with high access complexity and only partial integrity impact, its FAUCET Risk Score is notably high at 97/100, suggesting a greater real-world risk. The vulnerability is categorized as CWE-79 (Improper Neutralization of Input During Web Page Generation). Despite no evidence of active exploitation in the KEV catalog or Metasploit, an exploit for Microsoft Exchange Server 2000/2003 OWA script injection is available on ExploitDB. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2000:sp1:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2000:sp2:*:*:*:*:*:* | ||
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.