CVE-2012-0315
22.02.2012, 13:54
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.Enginsight
Vendor | Product | Version |
---|---|---|
estsoft | alftp | 𝑥 ≤ 5.1 |
estsoft | alftp | 4.1 |
estsoft | alftp | 4.1:beta2 |
estsoft | alftp | 4.1:beta2 |
estsoft | alftp | 5.0 |
estsoft | alftp | 5.1:beta2 |
𝑥
= Vulnerable software versions
References