Untrusted search path vulnerability in FFFTP before 1.98d allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file, a different vulnerability than CVE-2011-3991. Per: http://cwe.mitre.org/data/definitions/426.html
'CWE-426: Untrusted Search Path'
Publication date: Tue, 13 Dec 2011 17:55:00 +0000