HIGH · 7.5

CVE-2000-0640

Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or n...

Vulnerability Description

Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Steve PoulsenGuildftpd0.9.7

References

FAQ

What is CVE-2000-0640?

CVE-2000-0640 is a vulnerability with a CVSS score of 7.5 (HIGH). Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or n...

How severe is CVE-2000-0640?

CVE-2000-0640 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2000-0640?

Check the references section above for vendor advisories and patch information. Affected products include: Steve Poulsen Guildftpd.