Описание
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Broken Link
- Broken LinkPatch
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Broken Link
- Broken LinkPatch
Уязвимые конфигурации
Конфигурация 1Версия до 5.1 (включая)
Одно из
cpe:2.3:a:estsoft:alftp:*:*:*:*:*:*:*:*
cpe:2.3:a:estsoft:alftp:4.1:*:*:*:*:*:*:*
cpe:2.3:a:estsoft:alftp:4.1:beta2:*:*:*:*:*:*
cpe:2.3:a:estsoft:alftp:4.1:beta2:*:en:*:*:*:*
cpe:2.3:a:estsoft:alftp:5.0:*:*:*:*:*:*:*
cpe:2.3:a:estsoft:alftp:5.1:beta2:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00558
Низкий
9.3 Critical
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.
EPSS
Процентиль: 68%
0.00558
Низкий
9.3 Critical
CVSS2
Дефекты
NVD-CWE-Other