Vulnerabilities (CVE)

Filtered by vendor Argosoft Subscribe
Total 26 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0519 1 Argosoft 1 Ftp Server 2025-04-03 10.0 HIGH N/A
ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.
CVE-2005-0520 1 Argosoft 1 Ftp Server 2025-04-03 10.0 HIGH N/A
ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.
CVE-2002-1004 1 Argosoft 1 Argosoft Mail Server 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.
CVE-2004-1428 1 Argosoft 1 Ftp Server 2025-04-03 5.0 MEDIUM N/A
ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
CVE-2002-1005 1 Argosoft 1 Argosoft Mail Server 2025-04-03 5.0 MEDIUM N/A
ArGoSoft Mail Server 1.8.1.7 and earlier allows a webmail user to cause a denial of service (CPU consumption) by forwarding the email to the user while autoresponse is enabled, which creates an infinite loop.
CVE-2020-23824 1 Argosoft 1 Mail Server 2024-11-21 6.8 MEDIUM 8.8 HIGH
ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will run the CSRF.