The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Serv-u | Cat_soft | 2.4 (including) | 2.4 (including) |
Serv-u | Cat_soft | 2.5 (including) | 2.5 (including) |
Serv-u | Cat_soft | 2.5a (including) | 2.5a (including) |
Serv-u | Cat_soft | 2.5b (including) | 2.5b (including) |
Serv-u | Cat_soft | 2.5c (including) | 2.5c (including) |
Serv-u | Cat_soft | 2.5d (including) | 2.5d (including) |