Korean
<< Back
VID 16138
Severity 30
Port 21
Protocol TCP
Class FTP
Detailed Description The remote host is running Serv-U File Server, an FTP server for Windows. According to its banner, the installed version of Serv-U is earlier than 9.2.0.1, and therefore affected by the following issues :

- The installed version of Serv-U is earlier than 9.2.0.1 and as such is reportedly affected by an information disclosure vulnerability.

An authenticated user can exploit this to view directories above his or her root directory.

* Note: This check solely relied on the version number of the remote FTP server to assess this vulnerability, so this might be a false positive.

* References:
http://www.serv-u.com/releasenotes/

* Platforms Affected:
Rhino Software, Inc., Serv-U FTP Server 9.2.0.1 prior
Microsoft Windows Any version
Recommendation Upgrade to latest version of Serv-U (9.2.0.1 or later), available from Serv-U Web site at http://www.serv-u.com/
Related URL CVE-2009-4815 (CVE)
Related URL 37414 (SecurityFocus)
Related URL (ISS)