This script is Copyright (C) 2000-2011 Tenable Network Security, Inc.
The remote FTP server is affected by an information disclosure
The remote FTP server can be used to determine if a given
file exists on the remote host or not, by adding dot-dot-slashes
in front of them. This is caused by the server responding with
different error messages depending on if the file exists or not.
An attacker may use this flaw to gain more knowledge about
this host, such as its file layout. This flaw is specially
useful when used with other vulnerabilities.
See also :
Upgrade to GuildFTPd 0.999.6 or later, as this reportedly fixes the
Risk factor :
High / CVSS Base Score : 7.5
CVSS Temporal Score : 5.5
Nessus Plugin ID: 10471 (guild_ftp.nasl)
Bugtraq ID: 1452
CVE ID: CVE-2000-0640
Upgrade to Nessus Professional today!
Start your free Nessus Cloud trial now!
Begin Free Trial
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.