peter bassill · operator
$ cve CVE-2010-2091 JSON

CVE-2010-2091 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 17.9% (pctl 97)

Patch early

A public exploit exists.

Description

Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS17.94% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2010-05-27
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftexchange server
microsoftinternet explorer
microsoftwindows server 2003

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD