Kerio MailServer Web Mail DO_MAP Module Cross-Site Scripting Vulnerability
BID:7968
Info
Kerio MailServer Web Mail DO_MAP Module Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7968 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0488 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to "David F.Madrid" <[email protected]>. |
| Vulnerable: |
Kerio Mailserver 5.6.3 |
| Not Vulnerable: |
Kerio Mailserver 5.6.4 |
Discussion
Kerio MailServer Web Mail DO_MAP Module Cross-Site Scripting Vulnerability
Reportedly, Kerio Mailserver is vulnerable to a cross site-scripting attack. The vulnerability is present in the do_map module of the Kerio Mailserver web mail component.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link containing malicious HTML code.
It should be noted that although this vulnerability has been reported to affect Kerio MailServer version 5.6.3, previous versions might also be affected.
Reportedly, Kerio Mailserver is vulnerable to a cross site-scripting attack. The vulnerability is present in the do_map module of the Kerio Mailserver web mail component.
An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link containing malicious HTML code.
It should be noted that although this vulnerability has been reported to affect Kerio MailServer version 5.6.3, previous versions might also be affected.
Exploit / POC
Kerio MailServer Web Mail DO_MAP Module Cross-Site Scripting Vulnerability
The following proof of concept has been provided:
http://www.example.com/do_map?action=new&oldalias=eso&alias=<script>alert(document.cookie);</script>&folder=public&user=lucascavadora
The following proof of concept has been provided:
http://www.example.com/do_map?action=new&oldalias=eso&alias=<script>alert(document.cookie);</script>&folder=public&user=lucascavadora
References
Kerio MailServer Web Mail DO_MAP Module Cross-Site Scripting Vulnerability
References:
References:
- Kerio Homepage (Kerio)
- Multiple buffer overflows and XSS in Kerio MailServer ("David F.Madrid"
)