Vulnerabilities > CVE-2000-0176 - Path Disclosure vulnerability in Serv-U FTP Server

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cat-soft
nessus

Summary

The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.

Nessus

NASL familyFTP
NASL idFTP_SERVU_PATH_DISCLOSURE.NASL
descriptionThe remote FTP server discloses the full path to its root through a CWD command for a nonexistent directory. In addition, the server may be prone to a buffer overflow that may allow a remote, authenticated attacker to launch a denial of service attack against the affected software.
last seen2020-06-01
modified2020-06-02
plugin id11392
published2003-03-15
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11392
titleServ-U < 2.5e Multiple Vulnerabilities (OF, Path Disc)