EUVD Vulnerability Catalog
Actively Exploited (KEV)
EUVD-2015-3352
Severity: CRITICAL
Base Score: 10
CVSS Version: 3.1
Vulnerability Description
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Changed
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
n/a
References & Advisory Links
- http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec
- https://www.exploit-db.com/exploits/36803/
- http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.html
- http://www.debian.org/security/2015/dsa-3263
- http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html
- http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.html
- http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html
- http://www.securityfocus.com/bid/74238
- https://www.exploit-db.com/exploits/36742/
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html
- http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.html
- http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.html
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
mitre
EPSS Probability
96.75
Known Aliases
GHSA-4mfj-5wr8-x32q
CVE-2015-3306
Published On
2015-05-18
Last Updated
2026-10-08
Exploited Since
2026-10-08