PT-2003-1662 · Kerio · Kerio Mailserver
David F. Madrid
·
Publicado
2003-06-28
·
Atualizado
2017-07-11
·
CVE-2003-0488
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Kerio MailServer version 5.6.3
Description:
The issue concerns multiple cross-site scripting (XSS) vulnerabilities and buffer-overrun vulnerabilities in the web mail component. An attacker can exploit the XSS vulnerabilities by enticing a victim user to follow a malicious link, potentially allowing the insertion of arbitrary web script via the
add name parameter in the add acl module or the alias parameter in the do map module. Additionally, buffer-overrun vulnerabilities can occur when handling usernames of excessive length, potentially resulting in the execution of arbitrary code with the privileges of the Kerio Mail Server process.Recommendations:
For Kerio MailServer version 5.6.3, consider disabling the
add acl and do map modules until a patch is available. Restrict access to the web mail component to minimize the risk of exploitation. Avoid using the add name and alias parameters in the affected modules until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kerio Mailserver