GuildFTPd Traversal Arbitrary File Enumeration
High Nessus Plugin ID 10471
SynopsisThe remote FTP server is affected by an information disclosure vulnerability.
DescriptionThe remote FTP server can be used to determine if a given file exists on the remote host or not, by adding dot-dot-slashes in front of them. This is caused by the server responding with different error messages depending on if the file exists or not.
An attacker may use this flaw to gain more knowledge about this host, such as its file layout. This flaw is specially useful when used with other vulnerabilities.
SolutionUpgrade to GuildFTPd 0.999.6 or later, as this reportedly fixes the issue.