WSFTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
Ipswitch WSFTP Server 4.0.2 has a backdoor XXSESSMGRYY username with a default password, which allows remote attackers to gain access.
Buffer overflow in WSFTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.
Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WSFTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors.
Format string vulnerability in the SCP module in Ipswitch WSFTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WSFTP script command.