A vulnerability exists in the Microsoft Exchange Server 5.5 Outlook Web Access (OWA) service that lets an attacker take any action on the user’s mailbox that the user can take, including deleting, moving and sending messages. The way OWA handles inline script message used in conjunction with Internet Explorer (IE) created a loophole for malicious users. The...
more