FreeBSD Security Advisory – The ftpd server splits long commands into several requests. This may result in the server executing a command which is hidden inside another very long command. This could, with a specifically crafted command, be used in a cross-site request forgery attack.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/73372/FreeBSD-SA-08-12.ftpd.txt
Source: https://packetstormsecurity.com/files/73372/FreeBSD-Security-Advisory-XSRF-In-ftpd.html