Untrusted search path vulnerability in ALFTP before 5.31 allows local users to gain privileges via a Trojan horse executable file in a directory that is accessed for reading an extensionless file, as demonstrated by executing the README.exe file when a user attempts to access the README file. Per: http://cwe.mitre.org/data/definitions/426.html
'CWE-426: Untrusted Search Path'
Publication date: Wed, 22 Feb 2012 19:54:00 +0000