2000-03-22 05:00:00
mitre
PUBLISHED
The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.