ArGoSoft Mail Server Directory Traversal Vulnerability

ArGoSoft Mail Server is an STMP, POP3 and Finger server for Microsoft Windows environments. ArGoSoft has a built in web server to enable remote access to mail.

A directory traversal issue has been reported in the web server, which could allow remote users access to all files residing on the host.

This is accomplished by submitting a specially crafted request containing '/..' character sequences to a specific directory.

This issue is reported to exist in ArGoSoft Mail Server 1.8.1.5, earlier versions may also be affected by this issue.


 

Privacy Statement
Copyright 2010, SecurityFocus