Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Kerio MailServer Web Mail DO_MAP Module Cross-Site Scripting Vulnerability

Reportedly, Kerio Mailserver is vulnerable to a cross site-scripting attack. The vulnerability is present in the do_map module of the Kerio Mailserver web mail component.

An attacker may exploit this vulnerability by enticing a victim user to follow a malicious link containing malicious HTML code.

It should be noted that although this vulnerability has been reported to affect Kerio MailServer version 5.6.3, previous versions might also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus