← Vulnerability feed

Vulnerability record · CVE-2005-1284 · published 2 May 2005

CVE-2005-1284: Argosoft mail server vulnerability

Argosoft · Argosoft Mail Server

The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if "Allow Creation of Accounts From the Web Interface" is disabled, via a direct HTTP POST request.

7.5 CVSS 2.0 High EPSS 1.5% · top 26.0%
7.5CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if "Allow Creation of Accounts From the Web Interface" is disabled, via a direct HTTP POST request.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1284 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2005-1283Argosoft mail server vulnerabilityMultiple directory traversal vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote authenticated users to (1) read arbitrary files via the…EPSS 1.7%5.0CVE-2006-0928Argosoft mail server vulnerabilityThe POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP command, which reveals the oper…EPSS 2.1%5.0CVE-2002-1004Argosoft mail server vulnerabilityDirectory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrar…EPSS 8.3%5.0CVE-2002-1005Argosoft mail server vulnerabilityArGoSoft Mail Server 1.8.1.7 and earlier allows a webmail user to cause a denial of service (CPU consumption) by forwarding the email to the user whi…EPSS 2.0%4.6CVE-2005-0367Argosoft mail server vulnerabilityMultiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary fi…EPSS 1.9%4.3CVE-2006-0978Argosoft mail server vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow rem…EPSS 2.2%4.3CVE-2005-1282Argosoft mail server vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML…EPSS 1.2%4.3CVE-2002-1893Argosoft mail server vulnerabilityCross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2005-1284), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.