← back
CVE-2015-3306

CVE-2015-3306

65Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 97%
from disclosure to weapon0 days
Published on NVDMay 18
1st PoCApr 13
metasploitApr 22
exploitation probability
97%top 1% of all CVEs
observed exploitation
nono source reports it
28 public exploit(s)
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Affected products
n/a · n/a
public PoCs found28 VexDay Proof
exploitdbVexDay Proofwww.exploit-db.com/exploits/49908exploitdbVexDay Proofwww.exploit-db.com/exploits/37262exploitdbVexDay Proofwww.exploit-db.com/exploits/36742exploitdbwww.exploit-db.com/exploits/36803unverifiedgithubgithub.com/t0kx/exploit-CVE-2015-3306151githubgithub.com/nootropics/propane2githubgithub.com/bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report1githubgithub.com/xyk0x/cpx_proftpd1githubgithub.com/davidtavarez/CVE-2015-33061githubgithub.com/0xm4ud/ProFTPD_CVE-2015-33061githubgithub.com/jptr218/proftpd_bypass1githubgithub.com/cybersensei-EH/hackviser_labs_CVE-2015-33061githubgithub.com/cd6629/CVE-2015-3306-Python-PoC1githubgithub.com/JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution0githubgithub.com/netw0rk7/CVE-2015-3306-Home-Lab0githubgithub.com/Z3R0space/CVE-2015-33060githubgithub.com/cved-sources/cve-2015-33060githubgithub.com/hackarada/cve-2015-33060githubgithub.com/cdedmondson/Modified-CVE-2015-3306-Exploit0githubgithub.com/donmedfor/CVE-2015-33060githubgithub.com/canpilayda/proftpd-mod_copy-cve-2015-33060cve_referencewww.exploit-db.com/exploits/36742/unverifiedcve_referencewww.exploit-db.com/exploits/36803/unverifiedcve_referencepacketstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.htmlunverifiedcve_referencepacketstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.htmlunverifiedcve_referencepacketstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.htmlunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.