|
Microsoft Exchange's Outlook Web Access (OWA) contains a flaw that allows a remote attacker to send a malicious e-mail that triggers the execution of hostile script. By sending a specially-crafted URL without the "security" parameter, a victim would not be protected by the built in security filter. Such a URL could contain an embedded link with the body of an HTML email message that modifies settings, manipulates e-mail, or steals the user authentication credentials.
|