PT-2015-1244 · Proftpd+1 · Proftpd+1

R-73En

·

Published

2015-05-18

·

Updated

2026-03-10

·

CVE-2015-3306

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProFTPD version 1.3.5
Description The issue allows remote attackers to read and write to arbitrary files. This is achieved via the site cpfr and site cpto commands, which are part of the mod copy module in the ProFTPD FTP server.
Recommendations For ProFTPD version 1.3.5, consider disabling the mod copy module as a temporary workaround until a patch is available. Restrict access to the site cpfr and site cpto commands to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2329
ALT-PU-2019-2647
BDU:2015-10225
CVE-2015-3306
DSA-3263-1
OPENSUSE-SU-2024:10048-1

Affected Products

Alt Linux
Proftpd