PT-2005-2287 · Argosoft · Argosoft Mail Server Pro
Shineshadow
·
Publicado
2005-04-26
·
Atualizado
2017-07-11
·
CVE-2005-1284
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Argosoft Mail Server Pro version 1.8.7.6
Description:
The issue allows remote attackers to create arbitrary accounts in Argosoft Mail Server Pro, even when the "Allow Creation of Accounts From the Web Interface" option is disabled. This can be achieved via a direct HTTP POST request to the addnew script.
Recommendations:
For Argosoft Mail Server Pro version 1.8.7.6, consider disabling the addnew script until a patch is available to prevent remote attackers from creating arbitrary accounts. Restrict access to the web interface to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Argosoft Mail Server Pro