The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if "Allow Creation of Accounts From the Web Interface" is disabled, via a direct HTTP POST request.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/13323 | vdb entry |
http://marc.info/?l=bugtraq&m=111419001527077&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20228 | vdb entry |
http://www.osvdb.org/15822 | vdb entry |