| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.10565 |
| Category: | FTP |
| Title: | Serv-U Directory traversal |
| Summary: | Traverses the remote ftp root |
| Description: | It is possible to break out of the remote FTP chroot by appending %20s in the CWD command, as in : CWD ..%20. This problem allows an attacker to browse the entire remote disk Solution : Upgrade to Serv-U 2.5i Risk factor : High |
| Cross-Ref: |
BugTraq ID: 2052 Common Vulnerability Exposure (CVE) ID: CVE-2001-0054 Bugtraq: 20001205 Serv-U FTP directory traversal vunerability (all versions) (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=97604119024280&w=2 Bugtraq: 20001205 (no subject) (Google Search) http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html http://www.securityfocus.com/bid/2052 XForce ISS Database: ftp-servu-homedir-travers http://xforce.iss.net/static/5639.php http://www.osvdb.org/464 |
| Copyright | This script is Copyright (C) 2000 Renaud Deraison |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|