Serv-U <

Medium Nessus Plugin ID 41980


The remote FTP server is affected by multiple vulnerabilities.


The installed version of Serv-U is earlier than and as such is reportedly affected by following issues :

- Provided 'SITE SET' command is enabled, an authorized user may be able to crash the remote FTP server by sending a specially crafted 'SITE SET TRANSFERPROGRESS ON' command.

- An unprivileged user may be able to view all drives and virtual paths for drive '\'.


Upgrade to Serv-U version or later.

See Also

Plugin Details

Severity: Medium

ID: 41980

File Name: servu_9_0_0_1.nasl

Version: $Revision: 1.9 $

Type: remote

Family: FTP

Published: 2009/10/05

Modified: 2011/12/09

Dependencies: 48434

Risk Information

Risk Factor: Medium


Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:serv-u:serv-u

Required KB Items: ftp/servu

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2009/09/29

Vulnerability Publication Date: 2009/09/29

Reference Information

BID: 36585

OSVDB: 58459

Secunia: 36873