First published: Tue Feb 29 2000(Updated: )
The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U | =2.4 | |
SolarWinds Serv-U | =2.5 | |
SolarWinds Serv-U | =2.5a | |
SolarWinds Serv-U | =2.5b | |
SolarWinds Serv-U | =2.5c | |
SolarWinds Serv-U | =2.5d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0176 is classified as a moderate severity vulnerability due to the potential exposure of sensitive path information.
To fix CVE-2000-0176, upgrade to a version of Serv-U that is newer than 2.5d where the vulnerability has been addressed.
CVE-2000-0176 can facilitate directory traversal attacks allowing attackers to reveal the filesystem structure.
CVE-2000-0176 affects SolarWinds Serv-U versions 2.4, 2.5, and all prior versions up to 2.5d.
Yes, CVE-2000-0176 can be exploited remotely by sending requests for non-existent files or directories.