CVE-2009-2636
Kerio MailServer <6.7.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Integration page in the WebMail component in Kerio MailServer 6.6.0, 6.6.1, 6.6.2, and 6.7.0 allows remote attackers to inject arbitrary web script or HTML via an e-mail message.
Scores
EPSS
0.0036
EPSS Percentile
57.6%
Classification
CWE
CWE-79
Status
published
Affected Products (5)
kerio/kerio_mailserver
kerio/kerio_mailserver
kerio/kerio_mailserver
kerio/kerio_mailserver
n/a/n/a
Timeline
Published
Jul 28, 2009
Tracked Since
Feb 18, 2026