This CPE summary could be partial or incomplete. Please contact us for a detailed listing.


Vendor Microsoft First view 2016-01-13
Product Exchange Server Last view 2019-07-15
Version 2013 Type Application
Update cumulative_update_11  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
CPE Product cpe:2.3:a:microsoft:exchange_server

Activity : Overall

Related : CVE

  Date Alert Description
5.4 2019-07-15 CVE-2019-1137

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

6.1 2016-01-13 CVE-2016-0032

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulative Update 11, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability."

CWE : Common Weakness Enumeration

100% (2) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Nessus® Vulnerability Scanner

id Description
2016-01-13 Name: The remote Microsoft Exchange server is affected by multiple spoofing vulnera...
File: smb_nt_ms16-010.nasl - Type: ACT_GATHER_INFO