See how ftp compares to other vendors in security performance
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.
FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client.
A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.
CWD ~root command in ftpd allows root access.