SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.Referenceshttp://www.securityfocus.com/bid/1344https://exchange.xforce.ibmcloud.com/vulnerabilities/4706http://www.osvdb.org/1394http://archives.neohapsis.com/archives/bugtraq/2000-06/0100.html