20030618 Multiple buffer overflows and XSS in Kerio MailServermailing list
http://marc.info/?l=bugtraq&m=105596982503760&w=2 CVE-2003-0487
Kerio MailServer 5.6.3 subscribe Module - Overflow
Record summary
CVE-2003-0487 has a selected CVSS score of 7.5; EIP currently links 5 catalogued exploits.
Description
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 5
Proofs of concept
5Catalogued exploits
ExploitDBKerio MailServer 5.6.3 subscribe Module - OverflowExploitDB exploitby David F.MadridNot analyzed1 file
ExploitDBKerio MailServer 5.6.3 add_acl Module - OverflowExploitDB exploitby David F.MadridNot analyzed1 file
ExploitDBKerio MailServer 5.6.3 list Module - OverflowExploitDB exploitby David F.MadridNot analyzed1 file
ExploitDBKerio MailServer 5.6.3 do_map Module - OverflowExploitDB exploitby David F.MadridNot analyzed1 file
ExploitDBKerio MailServer 5.6.3 - Remote Buffer OverflowExploitDB exploitby B-r00tNot analyzed1 file
References
5nautopia.org
http://nautopia.org/vulnerabilidades/kerio_mailserver.htm 7967vdb entry
http://www.securityfocus.com/bid/7967 kerio-multiple-modules-bo(12368)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/12368 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0487