Back to Database
Status published
Critical
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to...
Vulnerability Description
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-3306
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec
- https://www.exploit-db.com/exploits/36803/
- http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html
- http://www.debian.org/security/2015/dsa-3263
- http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html
- http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html
- http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html
- http://www.securityfocus.com/bid/74238
- https://www.exploit-db.com/exploits/36742/
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html
- http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html
- http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html
More from proftpd
View All →CVE-2021-46854
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS...
Unknown
0
CVE-2020-9273
In ProFTPD 1.3.7, it is possible to corrupt the memory...
High
8.8
CVE-2020-9272
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap...
High
7.5
CVE-2019-19272
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6....
High
7.5
CVE-2019-19271
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6....
High
7.5
Affected Vendor
proftpd
View all reports →Affected Software
proftpd
Vulnerable Versions:
1.3.5
Timeline
Official Publish:
May 18th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.