PT-2003-1662 · Kerio · Kerio Mailserver
David F. Madrid
·
Published
2003-06-28
·
Updated
2017-07-11
·
CVE-2003-0488
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Kerio MailServer version 5.6.3
Description:
The issue concerns multiple cross-site scripting (XSS) vulnerabilities and buffer-overrun vulnerabilities in the web mail component. An attacker can exploit the XSS vulnerabilities by enticing a victim user to follow a malicious link, potentially allowing the insertion of arbitrary web script via the
add name parameter in the add acl module or the alias parameter in the do map module. Additionally, buffer-overrun vulnerabilities can occur when handling usernames of excessive length, potentially resulting in the execution of arbitrary code with the privileges of the Kerio Mail Server process.Recommendations:
For Kerio MailServer version 5.6.3, consider disabling the
add acl and do map modules until a patch is available. Restrict access to the web mail component to minimize the risk of exploitation. Avoid using the add name and alias parameters in the affected modules until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kerio Mailserver