Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
http://www.iss.net/security_center/static/9905.php
http://archives.neohapsis.com/archives/bugtraq/2002-08/0183.html