CVE-2011-4266
13.12.2011, 11:55
Untrusted search path vulnerability in FFFTP before 1.98d allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file, a different vulnerability than CVE-2011-3991.Enginsight
Vendor | Product | Version |
---|---|---|
ffftp | ffftp | 𝑥 ≤ 1.98 |
ffftp | ffftp | 1.79a:a |
ffftp | ffftp | 1.80 |
ffftp | ffftp | 1.81 |
ffftp | ffftp | 1.82 |
ffftp | ffftp | 1.83 |
ffftp | ffftp | 1.84 |
ffftp | ffftp | 1.85 |
ffftp | ffftp | 1.86 |
ffftp | ffftp | 1.86a:a |
ffftp | ffftp | 1.87 |
ffftp | ffftp | 1.87a:a |
ffftp | ffftp | 1.88 |
ffftp | ffftp | 1.88a:a |
ffftp | ffftp | 1.88b:b |
ffftp | ffftp | 1.89 |
ffftp | ffftp | 1.89a:a |
ffftp | ffftp | 1.89b:b |
ffftp | ffftp | 1.90 |
ffftp | ffftp | 1.91 |
ffftp | ffftp | 1.92 |
ffftp | ffftp | 1.92a:a |
ffftp | ffftp | 1.92b:b |
ffftp | ffftp | 1.92c:c |
ffftp | ffftp | 1.93 |
ffftp | ffftp | 1.94 |
ffftp | ffftp | 1.94a:a |
ffftp | ffftp | 1.95 |
ffftp | ffftp | 1.96 |
ffftp | ffftp | 1.96a:a |
ffftp | ffftp | 1.96b:b |
ffftp | ffftp | 1.96c:c |
ffftp | ffftp | 1.96d:d |
ffftp | ffftp | 1.97 |
ffftp | ffftp | 1.97a:a |
ffftp | ffftp | 1.97b:b |
ffftp | ffftp | 1.98 |
ffftp | ffftp | 1.98:a |
ffftp | ffftp | 1.98:b |
𝑥
= Vulnerable software versions