Vulnerabilities > CVE-2005-1283 - Unspecified vulnerability in Argosoft Mail Server 1.8.7.6
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN argosoft
nessus
Summary
Multiple directory traversal vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote authenticated users to (1) read arbitrary files via the UIDL parameter to the msg script or (2) copy or move the user's .eml file to arbitrary locations via the delete script, a different vulnerability than CVE-2005-0367.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | ARGOSOFT_1_8_7_6.NASL |
description | The version of ArGoSoft Mail Server Pro installed on the remote host suffers from several vulnerabilities, including : - Unauthenticated Account Creation Vulnerability The application does not authenticate requests sent through the web interface before creating mail accounts and may create them even if ArGoSoft has been configured not to. - Multiple Cross-Site Scripting Vulnerabilities ArGoSoft fails to filter some HTML tags in email messages; eg, the SRC parameter in an IMG tag. An attacker may be able to run arbitrary HTML and script code in a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18140 |
published | 2005-04-26 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18140 |
title | ArGoSoft Mail Server Pro <= 1.8.7.6 Multiple Vulnerabilities (XSS, Traversal, Priv Esc) |
code |
|
References
- http://marc.info/?l=bugtraq&m=111419001527077&w=2
- http://marc.info/?l=bugtraq&m=111419001527077&w=2
- http://www.osvdb.org/15821
- http://www.osvdb.org/15821
- http://www.osvdb.org/15823
- http://www.osvdb.org/15823
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20226
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20226
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20229
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20229