![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.80069 |
Category: | Gain a shell remotely |
Title: | Kerio WebMail < 5.7.7 Multiple Vulnerabilities |
Summary: | Kerio MailServer is prone to multiple vulnerabilities. |
Description: | Summary: Kerio MailServer is prone to multiple vulnerabilities. Vulnerability Insight: There are multiple flaws in this interface which may allow an attacker with a valid webmail account on this host to obtain a shell on this host or to perform a cross-site-scripting attack against this host with version prior to 5.6.4. Version of MailServer prior to 5.6.5 are also prone to a denial of service condition when an incorrect login to the admin console occurs. This could cause the server to crash. Version of MailServer prior to 5.7.7 is prone to a remotely exploitable buffer overrun condition. This vulnerability exists in the spam filter component. If successfully exploited, this could permit remote attackers to execute arbitrary code in the context of the MailServer software. This could also cause a denial of service in the server. Solution: Update to version 5.7.7 or later. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2002-1434 BugTraq ID: 5507 http://www.securityfocus.com/bid/5507 Bugtraq: 20020819 Kerio Mail Server Multiple Security Vulnerabilities (Google Search) http://archives.neohapsis.com/archives/bugtraq/2002-08/0183.html http://www.iss.net/security_center/static/9905.php Common Vulnerability Exposure (CVE) ID: CVE-2003-0487 BugTraq ID: 7967 http://www.securityfocus.com/bid/7967 Bugtraq: 20030618 Multiple buffer overflows and XSS in Kerio MailServer (Google Search) http://marc.info/?l=bugtraq&m=105596982503760&w=2 http://nautopia.org/vulnerabilidades/kerio_mailserver.htm XForce ISS Database: kerio-multiple-modules-bo(12368) https://exchange.xforce.ibmcloud.com/vulnerabilities/12368 Common Vulnerability Exposure (CVE) ID: CVE-2003-0488 BugTraq ID: 7966 http://www.securityfocus.com/bid/7966 BugTraq ID: 7968 http://www.securityfocus.com/bid/7968 XForce ISS Database: kerio-multiple-modules-xss(12367) https://exchange.xforce.ibmcloud.com/vulnerabilities/12367 |
Copyright | Copyright (C) 2008 Tenable Network Security & David Maciejak |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |