Vulnerability Details CVE-2012-0315
Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.5%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2012-0315
-
cpe:2.3:a:estsoft:alftp:4.1
-
cpe:2.3:a:estsoft:alftp:5.0
-
cpe:2.3:a:estsoft:alftp:5.1