The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.
| Software | From | Fixed in |
|---|---|---|
| cat_soft / serv-u | 2.4 | 2.4.x |
| cat_soft / serv-u | 2.5b | 2.5b.x |
| cat_soft / serv-u | 2.5c | 2.5c.x |
| cat_soft / serv-u | 2.5 | 2.5.x |
| cat_soft / serv-u | 2.5d | 2.5d.x |
| cat_soft / serv-u | 2.5a | 2.5a.x |