Vulnerability Details CVE-2000-0176
The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.1%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2000-0176
-
cpe:2.3:a:cat_soft:serv-u:2.4
-
cpe:2.3:a:cat_soft:serv-u:2.5
-
cpe:2.3:a:cat_soft:serv-u:2.5a
-
cpe:2.3:a:cat_soft:serv-u:2.5b
-
cpe:2.3:a:cat_soft:serv-u:2.5c
-
cpe:2.3:a:cat_soft:serv-u:2.5d