ArGoSoft Mail Server Pro IMAP RENAME Command Traversal Arbitrary Directory Creation

This script is Copyright (C) 2006-2016 Tenable Network Security, Inc.

Synopsis :

The remote IMAP server is subject to directory traversal attacks.

Description :

The remote host is running ArGoSoft Mail Server, a messaging system
for Windows.

The IMAP server bundled with the version of ArGoSoft Mail Server
installed on the remote host fails to filter directory traversal
sequences from mailbox names passed to the 'RENAME' command. An
authenticated attacker can exploit this issue to move mailboxes to any
location on the affected system.

See also :

Solution :

Upgrade to ArGoSoft Mail Server or later.

Risk factor :

Medium / CVSS Base Score : 4.0
CVSS Temporal Score : 3.8
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 20977 (argosoft_ms_imap_rename_dir_traversal.nasl)

Bugtraq ID: 16809

CVE ID: CVE-2006-0929

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now