VulnerabilityModified
CVE-2009-2636
Cross-site scripting (XSS) vulnerability in the Integration page in the WebMail component in Kerio MailServer 6.6.0, 6.6.1, 6.6.2, and 6.7.0 allows remote attackers to inject arbitrary web script or HTML via an e-mail message.
MEDIUM 4.3EPSS 1.06%
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Integration page in the WebMail component in Kerio MailServer 6.6.0, 6.6.1, 6.6.2, and 6.7.0 allows remote attackers to inject arbitrary web script or HTML via an e-mail message.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- kerio/kerio mailserver
- Source
- cve@mitre.org
References
- http://osvdb.org/54928
- http://secunia.com/advisories/35392Vendor Advisory
- http://www.kerio.com/support/security-advisories#0906Vendor Advisory
- http://www.securityfocus.com/bid/35264Patch
- http://www.securitytracker.com/id?1022348Patch
- http://osvdb.org/54928
- http://secunia.com/advisories/35392Vendor Advisory
- http://www.kerio.com/support/security-advisories#0906Vendor Advisory
- http://www.securityfocus.com/bid/35264Patch
- http://www.securitytracker.com/id?1022348Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.