[Japanese] | |
JVNDB-2014-000103 | |
EmFTP may insecurely load executable files | |
Overview | |
EmFTP contains a flaw when loading files, where an unitended executable file may be loaded when attempting to open a file without an extension. For example, if a text file named "exmaple" (without an extension) and an executable "example.exe" are in the same directory, attemtping to open the file "example" will result in the execution of "example.exe". | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 5.1 (Medium) [IPA Score]
| |
Affected Products | |
| |
Emurasoft, Inc. | |
| |
Impact | |
An attacker may execute arbitrary code with the privilege of the vulnerable application. | |
Solution | |
[Apply a workaround] | |
Vendor Information | |
Emurasoft, Inc. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2014/09/04 |
Date First Published | 2014/09/04 |
Date Last Updated | 2014/09/09 |