7.5
CVSSv2

CVE-2000-0640

Published: 08/07/2000 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Guild FTPd allows remote malicious users to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.

Vulnerable Product Search on Vulmon Subscribe to Product

steve poulsen guildftpd 0.9.7

Exploits

source: wwwsecurityfocuscom/bid/1452/info Guild Ftpd will not send files outside of the ftp root when they are specified by the / string in the path of the GET request However due to the difference in the error messages it is able to determine if the file requested exists The error message "Download failed" appears if the requested fi ...