PT-2005-2287 · Argosoft · Argosoft Mail Server Pro

Shineshadow

·

Published

2005-04-26

·

Updated

2017-07-11

·

CVE-2005-1284

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Argosoft Mail Server Pro version 1.8.7.6
Description: The issue allows remote attackers to create arbitrary accounts in Argosoft Mail Server Pro, even when the "Allow Creation of Accounts From the Web Interface" option is disabled. This can be achieved via a direct HTTP POST request to the addnew script.
Recommendations: For Argosoft Mail Server Pro version 1.8.7.6, consider disabling the addnew script until a patch is available to prevent remote attackers from creating arbitrary accounts. Restrict access to the web interface to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1284

Affected Products

Argosoft Mail Server Pro