Debian Security Advisory 1296-1 – It was discovered that the ftp extension of PHP, a server-side, HTML-embedded scripting language performs insufficient input sanitising, which permits an attacker to execute arbitrary FTP commands. This requires the attacker to already have access to the FTP server.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56892/dsa-1296-1.txt
Source: https://packetstormsecurity.com/files/56892/Debian-Linux-Security-Advisory-1296-1.html

