← Vulnerability feed

Vulnerability record · CVE-2015-3306 · published 18 May 2015

CVE-2015-3306: ProFTPD mod_copy arbitrary file read and write

PProftpd · Proftpd

The mod_copy module in ProFTPD 1.3.5 fails to restrict the SITE CPFR and SITE CPTO commands, letting remote attackers copy arbitrary files on the server. Because copied files can be placed in web-accessible or executable locations, the flaw enables both data disclosure and remote code execution.

10.0 CVSS 2.0 High EPSS 97% · top 0.1% CWE-284 · Improper access control
10.0CVSS 2.0 base score
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote file read/write with public exploit code and a CVSS 2.0 score of 10 makes this a critical exposure for any internet-facing ProFTPD 1.3.5 host.

What it is

The mod_copy module in ProFTPD 1.3.5 fails to restrict the SITE CPFR and SITE CPTO commands, letting remote attackers copy arbitrary files on the server. Because copied files can be placed in web-accessible or executable locations, the flaw enables both data disclosure and remote code execution.

Impact

An unauthenticated attacker can read sensitive files and write attacker-controlled content to arbitrary paths, which commonly leads to full remote command execution as the ProFTPD service account.

Attack surface

Reachable over the network through the FTP service on port 21; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required, and the description confirms remote exploitation via SITE CPFR/CPTO.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.96752, 99.884th percentile) and multiple references are tagged Exploit, including Exploit-DB entries and a Rapid7 Metasploit module, indicating public exploit code exists.

What to do

  • Upgrade ProFTPD to a version that fixes the mod_copy access control issue, or apply the vendor/distribution patch (Debian DSA-3263, Fedora, openSUSE advisories).
  • If mod_copy is not required, disable or remove the module and block SITE CPFR/CPTO commands.
  • Restrict FTP exposure to trusted networks and require strong authentication; do not expose port 21 to the internet where avoidable.
  • Run the ProFTPD service with least privilege and ensure its writable directories cannot be reached by a web server or executed.
  • Monitor and alert on SITE CPFR and SITE CPTO usage in FTP logs.

Detection

  • Search FTP logs for SITE CPFR and SITE CPTO commands, especially sequences copying files into web roots or script directories.
  • Alert on unexpected file creation or modification in web-accessible and executable paths owned by the FTP service account.
  • Monitor for outbound connections or child processes spawned by the ProFTPD process that indicate post-exploitation.
  • Correlate FTP session activity with subsequent web requests to newly written files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html
http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html
http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html
http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html
http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html
http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html
http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html
http://www.debian.org/security/2015/dsa-3263
http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec
http://www.securityfocus.com/bid/74238
https://www.exploit-db.com/exploits/36742/ Exploit
https://www.exploit-db.com/exploits/36803/ Exploit
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html
http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html
http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html
http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html
http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html
http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html
http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html
http://www.debian.org/security/2015/dsa-3263
http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec
http://www.securityfocus.com/bid/74238
https://www.exploit-db.com/exploits/36742/ Exploit
https://www.exploit-db.com/exploits/36803/ Exploit

Track CVE-2015-3306 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4221ProFTPD TELNET IAC handling stack buffer overflow allows remote code executionProFTPD before 1.3.3c contains multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c. A remote attacker can trigger t…EPSS 91%analysed9.8CVE-2019-12815ProFTPD mod_copy arbitrary file copy enables unauthenticated RCEmod_copy in ProFTPD up to 1.3.5b performs an arbitrary file copy without validating the source or destination, letting an unauthenticated remote clie…EPSS 58%analysed9.3CVE-2010-20103Proftpd vulnerabilityA malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor im…EPSS 5.1%9.0CVE-2011-4130Proftpd vulnerabilityUse-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors inv…EPSS 13%8.8CVE-2020-9273Proftpd use after free vulnerabilityIn ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool i…EPSS 12%8.7CVE-2026-63090Proftpd heap-based buffer overflow vulnerabilityProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privileg…EPSS 0.93%8.6CVE-2026-35025Proftpd link following vulnerabilityProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL …EPSS 0.51%8.1CVE-2026-42167Proftpd sql injection vulnerabilitymod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER reques…EPSS 7.3%

Source: NIST National Vulnerability Database (record CVE-2015-3306), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.