WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/6760http://www.securityfocus.com/bid/2957http://www.securityfocus.com/archive/1/194442