Multiple Vulnerabilities Exist in Kerio MailServer 5.0 for Windows XP/2000/NT
August 20, 2002
Reported August 19, 2002, byAbraham Lincoln Hao.
VERSION AFFECTED
· Kerio MailServer 5.0 for Windows XP/2000/NT
DESCRIPTION
Multiplevulnerabilities exist in Kerio MailServer 5.0 for Windows that could result ina Denial of Service (DoS) or cross-site scripting scenario. Sendingat least five SYN packets to any of a mail server's services (i.e., POP3, SMTP,IMAP, Secure IMAP, POP3S, Web-mail, and secure Web-mail services) can result inthat service not responding; however, the service will be available again afterseveral minutes. An attack that exploits this vulnerability consumes all systemresources. Several URLs provided in the Web-mail function allow cross-sitescripting, which could let any user who has Web-mail access execute maliciousscripts. The following URLs are vulnerable:
· http://localhost//login
· http://localhost//search
· http://localhost//settings
· http://localhost//new
· http://localhost//list
· http://localhost//logout
VENDOR RESPONSE
Thevendor, Kerio Technologies, has beennotified but has not yet released a patch for these vulnerabilities.
CREDIT
Discovered by AbrahamLincoln Hao of NSSI Research Labs.
About the Author
You May Also Like