Vulnerabilities > CVE-2003-0488 - Cross-Site Scripting vulnerability in Kerio Mailserver 5.6.3
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Kerio MailServer 5.6.3 Web Mail ADD_ACL Module Cross-Site Scripting Vulnerability. CVE-2003-0488. Webapps exploit for cgi platform id EDB-ID:22799 last seen 2016-02-02 modified 2003-06-18 published 2003-06-18 reporter David F.Madrid source https://www.exploit-db.com/download/22799/ title Kerio MailServer 5.6.3 Web Mail ADD_ACL Module Cross-Site Scripting Vulnerability description Kerio MailServer 5.6.3 Web Mail DO_MAP Module Cross-Site Scripting Vulnerability. CVE-2003-0488. Webapps exploit for cgi platform id EDB-ID:22804 last seen 2016-02-02 modified 2003-06-18 published 2003-06-18 reporter David F.Madrid source https://www.exploit-db.com/download/22804/ title Kerio MailServer 5.6.3 Web Mail DO_MAP Module Cross-Site Scripting Vulnerability
Nessus
NASL family | CGI abuses |
NASL id | KERIO_WEBMAIL_MULTIPLE_FLAWS.NASL |
description | The remote host is running version 5 of the Kerio MailServer. There are multiple flaws in this interface that could allow an attacker with a valid webmail account on this host to obtain a shell on this host or to perform a cross-site-scripting attack against this host with a version prior to 5.6.4. Versions of MailServer prior to 5.6.5 are also prone to a denial of service condition when an incorrect login to the admin console occurs. This could cause the server to crash. Versions of MailServer prior to 5.7.7 are prone to a remotely exploitable buffer overrun condition. This vulnerability exists in the spam filter component. If successfully exploited, this could permit remote attackers to execute arbitrary code in the context of the MailServer software. This could also cause a denial of service in the server. *** This might be a false positive, as Nessus did not have *** the proper credentials to determine if the remote Kerio *** is affected by this flaw. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11763 |
published | 2003-06-18 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11763 |
title | Kerio WebMail < 5.7.7 Multiple Vulnerabilities |
code |
|