CVE-2015-3306

critical

Description

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

References

https://github.com/diegslva/cve-2015-3306-lab

https://github.com/bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report

https://github.com/ShacharLF/Network-Scanner

https://github.com/preetideepaksoni/Penetration-Testing-Portfolio

https://github.com/melihercen/cve-scanner

https://github.com/Retr0wq/network-scanner

https://github.com/owlsecx/OSpecter

https://github.com/Zahid-secure/cve-walkthrough-labs

https://github.com/javierbros11/Vulnerability_scanner

https://github.com/Neelesh707/Security-writeups

https://github.com/canpilayda/proftpd-mod_copy-cve-2015-3306

https://github.com/netw0rk7/CVE-2015-3306-Home-Lab

https://github.com/cybersensei-EH/hackviser_labs_CVE-2015-3306

https://github.com/alpaykuzu/PortScanner-CVE-Tool

https://github.com/HariCyber-Sec/hackviser-cve-labs

https://github.com/Z3R0-0x30/CVE-2015-3306

https://github.com/jptr218/proftpd_bypass

https://www.tenable.com/blog/cve-2019-12815-improper-access-control-vulnerability-in-proftpd-disclosed

https://github.com/nootropics/propane

http://www.securityfocus.com/bid/74238

http://www.debian.org/security/2015/dsa-3263

http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html

http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html

http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html

http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html

http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html

http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html

Details

Source: Mitre, NVD

Published: 2015-05-18

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.96752