Kerio MailServer / Connect < 7.0.1 Administration Console File Disclosure and File Corruption Vulnerability
Medium Nessus Network Monitor Plugin ID 5561
SynopsisThe remote mail server is vulnerable to a file disclosure and corruption vulnerability.
DescriptionVersions of Kerio Mail Server / Connect earlier than 7.0.1 are potentially affected by a file disclosure and corruption vulnerability. An attacker, with full administrative rights, can modify the administrative console to change the product configuration to read or corrupt arbitrary files on the server.
SolutionUpgrade to Kerio Connect 7.0.1 or later.