CVE Details
CVE-2015-3306
ProFTPD Improper Access Control Vulnerability
Published: 2026-10-08
CVSS: 10 CRITICAL
Product: ProFTPD ProFTPD
Due Date: 2026-10-11
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
GitHub PoC
Warning: GitHub PoC repositories are unverified. Some may be fake
or contain malware. Use caution and review code before running anything.
FIRST EPSS
EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.
Timeline
CVE Stalker
KEV
MITRE
GitHub
FIRST (EPSS)
MITRE
CVSS
SSVC
References
Show Raw Data
| Key | Remaining Key | Value |
|---|---|---|
| containers > | cna > affected > 0 > product | n/a |
| containers > | cna > affected > 0 > vendor | n/a |
| containers > | cna > affected > 0 > versions > 0 > status | affected |
| containers > | cna > affected > 0 > versions > 0 > version | n/a |
| containers > | cna > datePublic | 2015-04-07T00:00:00.000Z |
| containers > | cna > descriptions > 0 > lang | en |
| containers > | cna > descriptions > 0 > value | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. |
| containers > | cna > problemTypes > 0 > descriptions > 0 > description | n/a |
| containers > | cna > problemTypes > 0 > descriptions > 0 > lang | en |
| containers > | cna > problemTypes > 0 > descriptions > 0 > type | text |
| containers > | cna > providerMetadata > dateUpdated | 2021-05-26T19:06:22.000Z |
| containers > | cna > providerMetadata > orgId | 8254265b-2729-46b6-b9e3-3dfca2d5bfca |
| containers > | cna > providerMetadata > shortName | mitre |
| containers > | cna > references > 0 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 0 > url | http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec |
| containers > | cna > references > 1 > name | 36803 |
| containers > | cna > references > 1 > tags > 0 | exploit |
| containers > | cna > references > 1 > tags > 1 | x_refsource_EXPLOIT-DB |
| containers > | cna > references > 1 > url | https://www.exploit-db.com/exploits/36803/ |
| containers > | cna > references > 2 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 2 > url | http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html |
| containers > | cna > references > 3 > name | DSA-3263 |
| containers > | cna > references > 3 > tags > 0 | vendor-advisory |
| containers > | cna > references > 3 > tags > 1 | x_refsource_DEBIAN |
| containers > | cna > references > 3 > url | http://www.debian.org/security/2015/dsa-3263 |
| containers > | cna > references > 4 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 4 > url | http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html |
| containers > | cna > references > 5 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 5 > url | http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html |
| containers > | cna > references > 6 > name | openSUSE-SU-2015:1031 |
| containers > | cna > references > 6 > tags > 0 | vendor-advisory |
| containers > | cna > references > 6 > tags > 1 | x_refsource_SUSE |
| containers > | cna > references > 6 > url | http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html |
| containers > | cna > references > 7 > name | FEDORA-2015-7164 |
| containers > | cna > references > 7 > tags > 0 | vendor-advisory |
| containers > | cna > references > 7 > tags > 1 | x_refsource_FEDORA |
| containers > | cna > references > 7 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html |
| containers > | cna > references > 8 > name | FEDORA-2015-6401 |
| containers > | cna > references > 8 > tags > 0 | vendor-advisory |
| containers > | cna > references > 8 > tags > 1 | x_refsource_FEDORA |
| containers > | cna > references > 8 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html |
| containers > | cna > references > 9 > name | 74238 |
| containers > | cna > references > 9 > tags > 0 | vdb-entry |
| containers > | cna > references > 9 > tags > 1 | x_refsource_BID |
| containers > | cna > references > 9 > url | http://www.securityfocus.com/bid/74238 |
| containers > | cna > references > 10 > name | 36742 |
| containers > | cna > references > 10 > tags > 0 | exploit |
| containers > | cna > references > 10 > tags > 1 | x_refsource_EXPLOIT-DB |
| containers > | cna > references > 10 > url | https://www.exploit-db.com/exploits/36742/ |
| containers > | cna > references > 11 > name | FEDORA-2015-7086 |
| containers > | cna > references > 11 > tags > 0 | vendor-advisory |
| containers > | cna > references > 11 > tags > 1 | x_refsource_FEDORA |
| containers > | cna > references > 11 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html |
| containers > | cna > references > 12 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 12 > url | http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html |
| containers > | cna > references > 13 > tags > 0 | x_refsource_MISC |
| containers > | cna > references > 13 > url | http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html |
| containers > | cna > x_legacyV4Record > CVE_data_meta > ASSIGNER | [email protected] |
| containers > | cna > x_legacyV4Record > CVE_data_meta > ID | CVE-2015-3306 |
| containers > | cna > x_legacyV4Record > CVE_data_meta > STATE | PUBLIC |
| containers > | cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > product_name | n/a |
| containers > | cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > version > version_data > 0 > version_value | n/a |
| containers > | cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > vendor_name | n/a |
| containers > | cna > x_legacyV4Record > data_format | MITRE |
| containers > | cna > x_legacyV4Record > data_type | CVE |
| containers > | cna > x_legacyV4Record > data_version | 4.0 |
| containers > | cna > x_legacyV4Record > description > description_data > 0 > lang | eng |
| containers > | cna > x_legacyV4Record > description > description_data > 0 > value | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. |
| containers > | cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > lang | eng |
| containers > | cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > value | n/a |
| containers > | cna > x_legacyV4Record > references > reference_data > 0 > name | http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec |
| containers > | cna > x_legacyV4Record > references > reference_data > 0 > refsource | MISC |
| containers > | cna > x_legacyV4Record > references > reference_data > 0 > url | http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec |
| containers > | cna > x_legacyV4Record > references > reference_data > 1 > name | 36803 |
| containers > | cna > x_legacyV4Record > references > reference_data > 1 > refsource | EXPLOIT-DB |
| containers > | cna > x_legacyV4Record > references > reference_data > 1 > url | https://www.exploit-db.com/exploits/36803/ |
| containers > | cna > x_legacyV4Record > references > reference_data > 2 > name | http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 2 > refsource | MISC |
| containers > | cna > x_legacyV4Record > references > reference_data > 2 > url | http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 3 > name | DSA-3263 |
| containers > | cna > x_legacyV4Record > references > reference_data > 3 > refsource | DEBIAN |
| containers > | cna > x_legacyV4Record > references > reference_data > 3 > url | http://www.debian.org/security/2015/dsa-3263 |
| containers > | cna > x_legacyV4Record > references > reference_data > 4 > name | http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 4 > refsource | MISC |
| containers > | cna > x_legacyV4Record > references > reference_data > 4 > url | http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 5 > name | http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 5 > refsource | MISC |
| containers > | cna > x_legacyV4Record > references > reference_data > 5 > url | http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 6 > name | openSUSE-SU-2015:1031 |
| containers > | cna > x_legacyV4Record > references > reference_data > 6 > refsource | SUSE |
| containers > | cna > x_legacyV4Record > references > reference_data > 6 > url | http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 7 > name | FEDORA-2015-7164 |
| containers > | cna > x_legacyV4Record > references > reference_data > 7 > refsource | FEDORA |
| containers > | cna > x_legacyV4Record > references > reference_data > 7 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 8 > name | FEDORA-2015-6401 |
| containers > | cna > x_legacyV4Record > references > reference_data > 8 > refsource | FEDORA |
| containers > | cna > x_legacyV4Record > references > reference_data > 8 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 9 > name | 74238 |
| containers > | cna > x_legacyV4Record > references > reference_data > 9 > refsource | BID |
| containers > | cna > x_legacyV4Record > references > reference_data > 9 > url | http://www.securityfocus.com/bid/74238 |
| containers > | cna > x_legacyV4Record > references > reference_data > 10 > name | 36742 |
| containers > | cna > x_legacyV4Record > references > reference_data > 10 > refsource | EXPLOIT-DB |
| containers > | cna > x_legacyV4Record > references > reference_data > 10 > url | https://www.exploit-db.com/exploits/36742/ |
| containers > | cna > x_legacyV4Record > references > reference_data > 11 > name | FEDORA-2015-7086 |
| containers > | cna > x_legacyV4Record > references > reference_data > 11 > refsource | FEDORA |
| containers > | cna > x_legacyV4Record > references > reference_data > 11 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 12 > name | http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 12 > refsource | MISC |
| containers > | cna > x_legacyV4Record > references > reference_data > 12 > url | http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 13 > name | http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html |
| containers > | cna > x_legacyV4Record > references > reference_data > 13 > refsource | MISC |
| containers > | cna > x_legacyV4Record > references > reference_data > 13 > url | http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html |
| containers > | adp > 0 > providerMetadata > orgId | af854a3a-2127-422b-91ae-364da2661108 |
| containers > | adp > 0 > providerMetadata > shortName | CVE |
| containers > | adp > 0 > providerMetadata > dateUpdated | 2024-08-06T05:39:32.231Z |
| containers > | adp > 0 > title | CVE Program Container |
| containers > | adp > 0 > references > 0 > tags > 0 | x_refsource_MISC |
| containers > | adp > 0 > references > 0 > tags > 1 | x_transferred |
| containers > | adp > 0 > references > 0 > url | http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec |
| containers > | adp > 0 > references > 1 > name | 36803 |
| containers > | adp > 0 > references > 1 > tags > 0 | exploit |
| containers > | adp > 0 > references > 1 > tags > 1 | x_refsource_EXPLOIT-DB |
| containers > | adp > 0 > references > 1 > tags > 2 | x_transferred |
| containers > | adp > 0 > references > 1 > url | https://www.exploit-db.com/exploits/36803/ |
| containers > | adp > 0 > references > 2 > tags > 0 | x_refsource_MISC |
| containers > | adp > 0 > references > 2 > tags > 1 | x_transferred |
| containers > | adp > 0 > references > 2 > url | http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html |
| containers > | adp > 0 > references > 3 > name | DSA-3263 |
| containers > | adp > 0 > references > 3 > tags > 0 | vendor-advisory |
| containers > | adp > 0 > references > 3 > tags > 1 | x_refsource_DEBIAN |
| containers > | adp > 0 > references > 3 > tags > 2 | x_transferred |
| containers > | adp > 0 > references > 3 > url | http://www.debian.org/security/2015/dsa-3263 |
| containers > | adp > 0 > references > 4 > tags > 0 | x_refsource_MISC |
| containers > | adp > 0 > references > 4 > tags > 1 | x_transferred |
| containers > | adp > 0 > references > 4 > url | http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html |
| containers > | adp > 0 > references > 5 > tags > 0 | x_refsource_MISC |
| containers > | adp > 0 > references > 5 > tags > 1 | x_transferred |
| containers > | adp > 0 > references > 5 > url | http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html |
| containers > | adp > 0 > references > 6 > name | openSUSE-SU-2015:1031 |
| containers > | adp > 0 > references > 6 > tags > 0 | vendor-advisory |
| containers > | adp > 0 > references > 6 > tags > 1 | x_refsource_SUSE |
| containers > | adp > 0 > references > 6 > tags > 2 | x_transferred |
| containers > | adp > 0 > references > 6 > url | http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html |
| containers > | adp > 0 > references > 7 > name | FEDORA-2015-7164 |
| containers > | adp > 0 > references > 7 > tags > 0 | vendor-advisory |
| containers > | adp > 0 > references > 7 > tags > 1 | x_refsource_FEDORA |
| containers > | adp > 0 > references > 7 > tags > 2 | x_transferred |
| containers > | adp > 0 > references > 7 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html |
| containers > | adp > 0 > references > 8 > name | FEDORA-2015-6401 |
| containers > | adp > 0 > references > 8 > tags > 0 | vendor-advisory |
| containers > | adp > 0 > references > 8 > tags > 1 | x_refsource_FEDORA |
| containers > | adp > 0 > references > 8 > tags > 2 | x_transferred |
| containers > | adp > 0 > references > 8 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html |
| containers > | adp > 0 > references > 9 > name | 74238 |
| containers > | adp > 0 > references > 9 > tags > 0 | vdb-entry |
| containers > | adp > 0 > references > 9 > tags > 1 | x_refsource_BID |
| containers > | adp > 0 > references > 9 > tags > 2 | x_transferred |
| containers > | adp > 0 > references > 9 > url | http://www.securityfocus.com/bid/74238 |
| containers > | adp > 0 > references > 10 > name | 36742 |
| containers > | adp > 0 > references > 10 > tags > 0 | exploit |
| containers > | adp > 0 > references > 10 > tags > 1 | x_refsource_EXPLOIT-DB |
| containers > | adp > 0 > references > 10 > tags > 2 | x_transferred |
| containers > | adp > 0 > references > 10 > url | https://www.exploit-db.com/exploits/36742/ |
| containers > | adp > 0 > references > 11 > name | FEDORA-2015-7086 |
| containers > | adp > 0 > references > 11 > tags > 0 | vendor-advisory |
| containers > | adp > 0 > references > 11 > tags > 1 | x_refsource_FEDORA |
| containers > | adp > 0 > references > 11 > tags > 2 | x_transferred |
| containers > | adp > 0 > references > 11 > url | http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html |
| containers > | adp > 0 > references > 12 > tags > 0 | x_refsource_MISC |
| containers > | adp > 0 > references > 12 > tags > 1 | x_transferred |
| containers > | adp > 0 > references > 12 > url | http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html |
| containers > | adp > 0 > references > 13 > tags > 0 | x_refsource_MISC |
| containers > | adp > 0 > references > 13 > tags > 1 | x_transferred |
| containers > | adp > 0 > references > 13 > url | http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > scope | CHANGED |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > version | 3.1 |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > baseScore | 10 |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > attackVector | NETWORK |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > baseSeverity | CRITICAL |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > vectorString | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > integrityImpact | HIGH |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > userInteraction | NONE |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > attackComplexity | LOW |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > availabilityImpact | HIGH |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > privilegesRequired | NONE |
| containers > | adp > 1 > metrics > 0 > cvssV3_1 > confidentialityImpact | HIGH |
| containers > | adp > 1 > metrics > 1 > other > type | ssvc |
| containers > | adp > 1 > metrics > 1 > other > content > id | CVE-2015-3306 |
| containers > | adp > 1 > metrics > 1 > other > content > role | CISA Coordinator |
| containers > | adp > 1 > metrics > 1 > other > content > options > 0 > Exploitation | active |
| containers > | adp > 1 > metrics > 1 > other > content > options > 1 > Automatable | no |
| containers > | adp > 1 > metrics > 1 > other > content > options > 2 > Technical Impact | total |
| containers > | adp > 1 > metrics > 1 > other > content > version | 2.0.3 |
| containers > | adp > 1 > metrics > 1 > other > content > timestamp | 2026-10-08T17:40:17.854858Z |
| containers > | adp > 1 > references > 0 > url | https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3306 |
| containers > | adp > 1 > references > 0 > tags > 0 | government-resource |
| containers > | adp > 1 > problemTypes > 0 > descriptions > 0 > lang | en |
| containers > | adp > 1 > problemTypes > 0 > descriptions > 0 > type | CWE |
| containers > | adp > 1 > problemTypes > 0 > descriptions > 0 > cweId | CWE-284 |
| containers > | adp > 1 > problemTypes > 0 > descriptions > 0 > description | CWE-284 Improper Access Control |
| containers > | adp > 1 > title | CISA ADP Vulnrichment |
| containers > | adp > 1 > providerMetadata > orgId | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| containers > | adp > 1 > providerMetadata > shortName | CISA-ADP |
| containers > | adp > 1 > providerMetadata > dateUpdated | 2026-10-08T17:41:47.548Z |
| cveMetadata > | assignerOrgId | 8254265b-2729-46b6-b9e3-3dfca2d5bfca |
| cveMetadata > | assignerShortName | mitre |
| cveMetadata > | cveId | CVE-2015-3306 |
| cveMetadata > | datePublished | 2015-05-18T15:00:00.000Z |
| cveMetadata > | dateReserved | 2015-04-15T00:00:00.000Z |
| cveMetadata > | dateUpdated | 2026-10-08T17:41:47.548Z |
| cveMetadata > | state | PUBLISHED |
| dataType | CVE_RECORD | |
| dataVersion | 5.2 |