Serv-U FTP Server Path Disclosure Vulnerability
BID:1016
Info
Serv-U FTP Server Path Disclosure Vulnerability
| Bugtraq ID: | 1016 |
| Class: | Design Error |
| CVE: |
CVE-2000-0176 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 29 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | Posted to bugtraq by Berk Ulsoy <[email protected]> on February 29, 2000. |
| Vulnerable: |
Cat Soft Serv-U 2.5 d Cat Soft Serv-U 2.5 c Cat Soft Serv-U 2.5 b Cat Soft Serv-U 2.5 a Cat Soft Serv-U 2.5 Cat Soft Serv-U 2.4 x |
| Not Vulnerable: | |
Discussion
Serv-U FTP Server Path Disclosure Vulnerability
The default settings for Serv-U cause the server to give out full physical path information in the following circumstances.
A user attempting to retreive a non-existant file or change to a non-existant directory will see:
550 /d:/ftproot/nonexist: No such file or directory.
A user changing to an existing directory will see:
250 Directory changed to /d:/ftproot/exist
This information could be used to simplify other attacks.
The default settings for Serv-U cause the server to give out full physical path information in the following circumstances.
A user attempting to retreive a non-existant file or change to a non-existant directory will see:
550 /d:/ftproot/nonexist: No such file or directory.
A user changing to an existing directory will see:
250 Directory changed to /d:/ftproot/exist
This information could be used to simplify other attacks.
Exploit / POC
Serv-U FTP Server Path Disclosure Vulnerability
see discussion
see discussion