WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/5196http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.htmlhttp://www.osvdb.org/5829