Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-1547Open Redirect in Microsoft Exchange Server

CWE-601Open Redirect5 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
63.1%
top 1.60%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedOct 21
Latest updateMay 1

Description

Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-2xm9-jvff-c46x: Open redirect vulnerability in exchweb/bin/redir2022-05-01
CVEList
CVE-2008-1547: Open redirect vulnerability in exchweb/bin/redir2008-10-21

💥Exploits & PoCs

2
Exploit-DB
Microsoft Outlook Web Access for Exchange Server 2003 - 'redir.asp' Open Redirection2008-10-15
Nuclei
Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection
CVE-2008-1547 — Open Redirect in Microsoft | cvebase