PT-2005-2287 · Argosoft · Argosoft Mail Server Pro
Shineshadow
·
Published
2005-04-26
·
Updated
2017-07-11
·
CVE-2005-1284
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Argosoft Mail Server Pro version 1.8.7.6
Description:
The issue allows remote attackers to create arbitrary accounts in Argosoft Mail Server Pro, even when the "Allow Creation of Accounts From the Web Interface" option is disabled. This can be achieved via a direct HTTP POST request to the addnew script.
Recommendations:
For Argosoft Mail Server Pro version 1.8.7.6, consider disabling the addnew script until a patch is available to prevent remote attackers from creating arbitrary accounts. Restrict access to the web interface to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Argosoft Mail Server Pro