When downloading a batch of files from an FTP server the mget command does not check for directory escapes. A specially crafted file on the FTP server could then potentially overwrite an existing file of the user.
Copyright © 2003-2005 Jacques Vidrine and contributors. Please see the source of this document for full copyright information.