peter bassill · operator
$ cve CVE-2002-1434 JSON

CVE-2002-1434 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 4.3% (pctl 91)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS4.31% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2003-04-11
Last modified2026-06-16

Affected (1)

VendorProduct
keriokerio mailserver

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD