Vulnerabilities > CVE-2002-1434 - Cross-Site Scripting vulnerability in Kerio MailServer Web Mail
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | Kerio MailServer 5.0/5.1 Web Mail Multiple Cross Site Scripting Vulnerabilities. CVE-2002-1434. Webapps exploit for cgi platform |
id | EDB-ID:21728 |
last seen | 2016-02-02 |
modified | 2002-08-19 |
published | 2002-08-19 |
reporter | Abraham Lincoln |
source | https://www.exploit-db.com/download/21728/ |
title | Kerio MailServer 5.0/5.1 Web Mail Multiple Cross-Site Scripting Vulnerabilities |
Nessus
NASL family | CGI abuses |
NASL id | KERIO_WEBMAIL_MULTIPLE_FLAWS.NASL |
description | The remote host is running version 5 of the Kerio MailServer. There are multiple flaws in this interface that could allow an attacker with a valid webmail account on this host to obtain a shell on this host or to perform a cross-site-scripting attack against this host with a version prior to 5.6.4. Versions of MailServer prior to 5.6.5 are also prone to a denial of service condition when an incorrect login to the admin console occurs. This could cause the server to crash. Versions of MailServer prior to 5.7.7 are prone to a remotely exploitable buffer overrun condition. This vulnerability exists in the spam filter component. If successfully exploited, this could permit remote attackers to execute arbitrary code in the context of the MailServer software. This could also cause a denial of service in the server. *** This might be a false positive, as Nessus did not have *** the proper credentials to determine if the remote Kerio *** is affected by this flaw. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11763 |
published | 2003-06-18 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11763 |
title | Kerio WebMail < 5.7.7 Multiple Vulnerabilities |
code |
|