New Search

Exchange HTML injection vulnerability - CVE-2015-2359 (MS15-064)

oval:org.mitre.oval:def:28928

Cross-site scripting (XSS) vulnerability in the web applications in Microsoft Exchange Server 2013 Cumulative Update 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors aka "Exchange HTML Injection Vulnerability."

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2012 R2
Class:
vulnerability
Reference(s):
  • CVE-2015-2359
Product(s):
  • Microsoft Exchange Server 2013