ArGoSoft Authentication Bypass Vulnerability
BID:7608
Info
ArGoSoft Authentication Bypass Vulnerability
| Bugtraq ID: | 7608 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2003 12:00AM |
| Updated: | May 15 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Ziv Kamir <[email protected]> |
| Vulnerable: |
ArGoSoft Mail Server FreeWare 1.8.3 .4 ArGoSoft Mail Server FreeWare 1.8.2 .6 |
| Not Vulnerable: | |
Discussion
ArGoSoft Authentication Bypass Vulnerability
A vulnerability has been reported for ArGoSoft Mail Server FreeWare version. The problem occurs due to the FreeWare version of ArGoSoft failing to carry out sufficient authentication before granting access to the user management interface. As a result, an unauthorized user may be capable of tampering with sensitive server settings or user information. Access to this interface may also allow for the disclosure of sensitive information such as username or passwords.
A vulnerability has been reported for ArGoSoft Mail Server FreeWare version. The problem occurs due to the FreeWare version of ArGoSoft failing to carry out sufficient authentication before granting access to the user management interface. As a result, an unauthorized user may be capable of tampering with sensitive server settings or user information. Access to this interface may also allow for the disclosure of sensitive information such as username or passwords.
Exploit / POC
ArGoSoft Authentication Bypass Vulnerability
This issue can be exploited with a web browser. The following proof of concept URL has been made available:
http://www.target.org/useradm
This issue can be exploited with a web browser. The following proof of concept URL has been made available:
http://www.target.org/useradm
Solution / Fix
ArGoSoft Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.