CVE-2012-0315
22.02.2012, 13:54
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.Enginsight
| Vendor | Product | Version | 
|---|---|---|
| estsoft | alftp | 𝑥 ≤ 5.1 | 
| estsoft | alftp | 4.1 | 
| estsoft | alftp | 4.1:beta2 | 
| estsoft | alftp | 4.1:beta2 | 
| estsoft | alftp | 5.0 | 
| estsoft | alftp | 5.1:beta2 | 
𝑥
= Vulnerable software versions
References