PT-2003-1662 · Kerio · Kerio Mailserver

David F. Madrid

·

Published

2003-06-28

·

Updated

2017-07-11

·

CVE-2003-0488

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Kerio MailServer version 5.6.3
Description: The issue concerns multiple cross-site scripting (XSS) vulnerabilities and buffer-overrun vulnerabilities in the web mail component. An attacker can exploit the XSS vulnerabilities by enticing a victim user to follow a malicious link, potentially allowing the insertion of arbitrary web script via the add name parameter in the add acl module or the alias parameter in the do map module. Additionally, buffer-overrun vulnerabilities can occur when handling usernames of excessive length, potentially resulting in the execution of arbitrary code with the privileges of the Kerio Mail Server process.
Recommendations: For Kerio MailServer version 5.6.3, consider disabling the add acl and do map modules until a patch is available. Restrict access to the web mail component to minimize the risk of exploitation. Avoid using the add name and alias parameters in the affected modules until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0488

Affected Products

Kerio Mailserver