Access Bypass in Microsoft Outlook Express 6.0 by Microsoft
CVE-2004-2694
Currently unrated
What is CVE-2004-2694?
Microsoft Outlook Express 6.0 contains a vulnerability that allows remote attackers to circumvent established access controls. By manipulating the 'BASE HREF' attribute with a target set to '_top', an attacker can load unauthorized content into the Outlook interface, which can aid in executing phishing schemes. This alteration compromises user security and exposes sensitive information, making it crucial for users to be aware of such threats.