wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.728
EPSS Ranking 98.7%