PT-2006-1973 · Argosoft · Argosoft Mail Server Pro

Published

2006-02-28

·

Updated

2011-03-08

·

CVE-2006-0930

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ArGoSoft Mail Server Pro version 1.8
Description The issue allows remote authenticated users to read arbitrary files. This is achieved by utilizing a .. (dot dot) in the UIDL parameter, which enables directory traversal.
Recommendations For ArGoSoft Mail Server Pro version 1.8, consider restricting access to the UIDL parameter to prevent directory traversal attacks until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0930

Affected Products

Argosoft Mail Server Pro