PT-2005-2287 · Argosoft · Argosoft Mail Server Pro

Shineshadow

·

Publicado

2005-04-26

·

Atualizado

2017-07-11

·

CVE-2005-1284

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Argosoft Mail Server Pro version 1.8.7.6
Description: The issue allows remote attackers to create arbitrary accounts in Argosoft Mail Server Pro, even when the "Allow Creation of Accounts From the Web Interface" option is disabled. This can be achieved via a direct HTTP POST request to the addnew script.
Recommendations: For Argosoft Mail Server Pro version 1.8.7.6, consider disabling the addnew script until a patch is available to prevent remote attackers from creating arbitrary accounts. Restrict access to the web interface to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1284

Produtos afetados

Argosoft Mail Server Pro