← back
CVE-2015-3306

CVE-2015-3306

EPSS 96.8%
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Affected products
n/a · n/a
public PoCs found28
githubgithub.com/t0kx/exploit-CVE-2015-3306148githubgithub.com/nootropics/propane2githubgithub.com/bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report1githubgithub.com/xyk0x/cpx_proftpd1githubgithub.com/davidtavarez/CVE-2015-33061githubgithub.com/0xm4ud/ProFTPD_CVE-2015-33061githubgithub.com/jptr218/proftpd_bypass1githubgithub.com/cd6629/CVE-2015-3306-Python-PoC1githubgithub.com/cybersensei-EH/hackviser_labs_CVE-2015-33061githubgithub.com/JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution0githubgithub.com/donmedfor/CVE-2015-33060githubgithub.com/netw0rk7/CVE-2015-3306-Home-Lab0githubgithub.com/canpilayda/proftpd-mod_copy-cve-2015-33060githubgithub.com/cved-sources/cve-2015-33060githubgithub.com/hackarada/cve-2015-33060githubgithub.com/cdedmondson/Modified-CVE-2015-3306-Exploit0githubgithub.com/Z3R0space/CVE-2015-33060cve_referencewww.exploit-db.com/exploits/36742/unverifiedcve_referencepacketstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.htmlunverifiedcve_referencepacketstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/36803/unverifiedexploitdbwww.exploit-db.com/exploits/37262unverifiedexploitdbwww.exploit-db.com/exploits/36803unverifiedexploitdbwww.exploit-db.com/exploits/49908unverifiedexploitdbwww.exploit-db.com/exploits/36742unverifiedcve_referencepacketstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.htmlunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →