PT-2005-2286 · Argosoft · Argosoft Mail Server Pro
Shineshadow
·
Published
2005-04-22
·
Updated
2017-07-11
·
CVE-2005-1283
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Argosoft Mail Server Pro version 1.8.7.6
Description:
The issue allows remote authenticated users to read arbitrary files or copy/move files to arbitrary locations. This is achieved via the
UIDL parameter to the "msg script" or through the "delete script".Recommendations:
For Argosoft Mail Server Pro version 1.8.7.6, consider restricting access to the
UIDL parameter in the "msg script" and limiting the functionality of the "delete script" to prevent copying or moving files to arbitrary locations until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Argosoft Mail Server Pro