Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-1559
http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf