ProFTPD mod_copy Information Disclosure

This script is Copyright (C) 2015-2016 Tenable Network Security, Inc.


Synopsis :

The remote host is running a ProFTPD module that is affected by an
information disclosure vulnerability.

Description :

The remote host is running a version of ProFTPD that is affected by an
information disclosure vulnerability in the mod_copy module due to the
SITE CPFR and SITE CPTO commands being available to unauthenticated
clients. An unauthenticated, remote attacker can exploit this flaw to
read and write to arbitrary files on any web accessible path on the
host.

See also :

http://bugs.proftpd.org/show_bug.cgi?id=4169

Solution :

Upgrade to ProFTPD 1.3.5a / 1.3.6rc1 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: FTP

Nessus Plugin ID: 84215 ()

Bugtraq ID: 74238

CVE ID: CVE-2015-3306

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now