Vulnerability record · CVE-2015-3306 · published 18 May 2015
CVE-2015-3306: ProFTPD mod_copy arbitrary file read and write
PProftpd · Proftpd
The mod_copy module in ProFTPD 1.3.5 fails to restrict the SITE CPFR and SITE CPTO commands, letting remote attackers copy arbitrary files on the server. Because copied files can be placed in web-accessible or executable locations, the flaw enables both data disclosure and remote code execution.
Description
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote file read/write with public exploit code and a CVSS 2.0 score of 10 makes this a critical exposure for any internet-facing ProFTPD 1.3.5 host.
What it is
The mod_copy module in ProFTPD 1.3.5 fails to restrict the SITE CPFR and SITE CPTO commands, letting remote attackers copy arbitrary files on the server. Because copied files can be placed in web-accessible or executable locations, the flaw enables both data disclosure and remote code execution.
Impact
An unauthenticated attacker can read sensitive files and write attacker-controlled content to arbitrary paths, which commonly leads to full remote command execution as the ProFTPD service account.
Attack surface
Reachable over the network through the FTP service on port 21; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required, and the description confirms remote exploitation via SITE CPFR/CPTO.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.96752, 99.884th percentile) and multiple references are tagged Exploit, including Exploit-DB entries and a Rapid7 Metasploit module, indicating public exploit code exists.
What to do
- Upgrade ProFTPD to a version that fixes the mod_copy access control issue, or apply the vendor/distribution patch (Debian DSA-3263, Fedora, openSUSE advisories).
- If mod_copy is not required, disable or remove the module and block SITE CPFR/CPTO commands.
- Restrict FTP exposure to trusted networks and require strong authentication; do not expose port 21 to the internet where avoidable.
- Run the ProFTPD service with least privilege and ensure its writable directories cannot be reached by a web server or executed.
- Monitor and alert on SITE CPFR and SITE CPTO usage in FTP logs.
Detection
- Search FTP logs for SITE CPFR and SITE CPTO commands, especially sequences copying files into web roots or script directories.
- Alert on unexpected file creation or modification in web-accessible and executable paths owned by the FTP service account.
- Monitor for outbound connections or child processes spawned by the ProFTPD process that indicate post-exploitation.
- Correlate FTP session activity with subsequent web requests to newly written files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3306 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3306), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.