See how ftp compares to other vendors in security performance
CWD ~root command in ftpd allows root access.
FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client.
A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.