6.8
CVSSv2

CVE-2002-1434

Published: 11/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote malicious users to execute HTML script as other users via certain URLs.

Vulnerable Product Search on Vulmon Subscribe to Product

kerio kerio mailserver 5.0

kerio kerio mailserver 5.1.1

kerio kerio mailserver 5.1

Exploits

source: wwwsecurityfocuscom/bid/5507/info Reportedly, Kerio Mailserver is vulnerable to cross site scripting attacks The vulnerability is present in Kerio Mailserver's web mail component An attacker may exploit this vulnerability by causing a victim user to follow a malicious link Exploitation may result in the compromise of authentic ...