CVE-2002-1434: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1434?
The severity of CVE-2002-1434 is considered to be medium as it allows remote attackers to execute scripts in the browsers of other users.
How do I fix CVE-2002-1434?
To fix CVE-2002-1434, you should apply the latest patches and updates provided by Kerio for the MailServer.
Who is affected by CVE-2002-1434?
CVE-2002-1434 affects users of Kerio MailServer versions 5.0, 5.1, and 5.1.1.
What types of attacks can CVE-2002-1434 enable?
CVE-2002-1434 can enable cross-site scripting (XSS) attacks, which can lead to unauthorized actions performed on behalf of other users.
Is CVE-2002-1434 easy to exploit?
Yes, CVE-2002-1434 is relatively easy to exploit, as it requires knowledge of specific URLs to trigger the XSS vulnerabilities.