# Exploit Title: Microsoft Office Outlook Web Access for Exchange Server 2003 XSRF Vulnerability # Date: 07/20/2010 # Author: anonymous # Tested on: Microsoft Office Outlook Web Access for Exchange Server 2003 A cross-site request forgery vulnerability in Microsoft Office Outlook Web Access for Exchange Server 2003 can be exploited to add an automatic forwarding rule (as PoC) to the authenticated user's account. PoC: