CVE-2009-2636: XSS
Cross-site scripting (XSS) vulnerability in the Integration page in the WebMail component in Kerio MailServer 6.6.0, 6.6.1, 6.6.2, and 6.7.0 allows remote attackers to inject arbitrary web script or HTML via an e-mail message.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2636?
CVE-2009-2636 is classified as a moderate severity vulnerability due to its potential to allow cross-site scripting attacks through email messages.
How do I fix CVE-2009-2636?
To fix CVE-2009-2636, users should upgrade their Kerio MailServer to a patched version that is not vulnerable.
What software versions are affected by CVE-2009-2636?
CVE-2009-2636 affects Kerio MailServer versions 6.6.0, 6.6.1, 6.6.2, and 6.7.0.
What kind of attacks can CVE-2009-2636 enable?
CVE-2009-2636 can enable remote attackers to execute arbitrary web scripts or HTML through crafted email messages.
Is CVE-2009-2636 exploitable remotely?
Yes, CVE-2009-2636 can be exploited remotely, allowing attackers to inject malicious scripts over the web.