PT-2005-2286 · Argosoft · Argosoft Mail Server Pro

Shineshadow

·

Published

2005-04-22

·

Updated

2017-07-11

·

CVE-2005-1283

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Argosoft Mail Server Pro version 1.8.7.6
Description: The issue allows remote authenticated users to read arbitrary files or copy/move files to arbitrary locations. This is achieved via the UIDL parameter to the "msg script" or through the "delete script".
Recommendations: For Argosoft Mail Server Pro version 1.8.7.6, consider restricting access to the UIDL parameter in the "msg script" and limiting the functionality of the "delete script" to prevent copying or moving files to arbitrary locations until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1283

Affected Products

Argosoft Mail Server Pro