CVE-2000-0176
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/02/2000
Last modified:
03/04/2025
Description
The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cat_soft:serv-u:2.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:cat_soft:serv-u:2.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:cat_soft:serv-u:2.5a:*:*:*:*:*:*:* | ||
cpe:2.3:a:cat_soft:serv-u:2.5b:*:*:*:*:*:*:* | ||
cpe:2.3:a:cat_soft:serv-u:2.5c:*:*:*:*:*:*:* | ||
cpe:2.3:a:cat_soft:serv-u:2.5d:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page