CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2003-0324
http://marc.info/?l=bugtraq&m=105344578100315&w=2
http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0074.html