GuildFTPd Traversal Arbitrary File Enumeration

high Nessus Plugin ID 10471

Synopsis

The remote FTP server is affected by an information disclosure vulnerability.

Description

The remote FTP server can be used to determine if a given file exists on the remote host or not, by adding dot-dot-slashes in front of them. This is caused by the server responding with different error messages depending on if the file exists or not.

An attacker may use this flaw to gain more knowledge about this host, such as its file layout. This flaw is specially useful when used with other vulnerabilities.

Solution

Upgrade to GuildFTPd 0.999.6 or later, as this reportedly fixes the issue.

See Also

http://aluigi.altervista.org/adv/guildftpd-dir-adv.txt

Plugin Details

Severity: High

ID: 10471

File Name: guild_ftp.nasl

Version: 1.36

Type: remote

Family: FTP

Published: 7/16/2000

Updated: 11/5/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2000-0640

CVSS v3

Risk Factor: High

Base Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 7/8/2000

Reference Information

CVE: CVE-2000-0640

BID: 1452