Kerio MailServer Web Mail Multiple Cross Site Scripting Vulnerabilities
BID:5507
Info
Kerio MailServer Web Mail Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 5507 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1434 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery credited to "Abraham Lincoln" <[email protected]>. |
| Vulnerable: |
Kerio Mailserver 5.1.1 Kerio Mailserver 5.1 Kerio Mailserver 5.0 |
| Not Vulnerable: | |
Discussion
Kerio MailServer Web Mail Multiple Cross Site Scripting Vulnerabilities
Reportedly, Kerio Mailserver is vulnerable to cross site scripting attacks. The vulnerability is present in Kerio Mailserver's web mail component.
An attacker may exploit this vulnerability by causing a victim user to follow a malicious link. Exploitation may result in the compromise of authentication data, or in script code taking actions as the authenticated user.
*** The vendor has stated that this is not a vulnerability.
*** Proof of concept has been provided.
Reportedly, Kerio Mailserver is vulnerable to cross site scripting attacks. The vulnerability is present in Kerio Mailserver's web mail component.
An attacker may exploit this vulnerability by causing a victim user to follow a malicious link. Exploitation may result in the compromise of authentication data, or in script code taking actions as the authenticated user.
*** The vendor has stated that this is not a vulnerability.
*** Proof of concept has been provided.
Exploit / POC
Kerio MailServer Web Mail Multiple Cross Site Scripting Vulnerabilities
The following proof of concepts were provided by "Abraham Lincoln" <[email protected]>:
http://keriowebmail/<script>alert('THisIsREAL0wned')</script>
http://keriowebmail/passwd<script>alert('VERYVULNERABLE')</script>
The following proof of concepts were provided by "Abraham Lincoln" <[email protected]>:
http://keriowebmail/<script>alert('THisIsREAL0wned')</script>
http://keriowebmail/passwd<script>alert('VERYVULNERABLE')</script>
Solution / Fix
Kerio MailServer Web Mail Multiple Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Kerio MailServer Web Mail Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Kerio Homepage (Kerio)