CVE-2015-3306

ProFTPD Improper Access Control Vulnerability

10.0
CVSS 3.1
96.8 %
EPSS (current)
2026-10-08
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: ProFTPD / ProFTPD

Published: 2015-05-18 · Due (CISA): 2026-10-11

CWE: CWE-284 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleinetwork/cves/2015/CVE-2015-3306.yamlProFTPd - Remote Code Execution–
exploitdb36742ProFTPd 1.3.5 - File Copy2015-04-13
exploitdb36803ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution2015-04-21
metasploitexploit/unix/ftp/proftpd_modcopy_execexploit/unix/ftp/proftpd_modcopy_exec2015-04-22
exploitdb37262ProFTPd 1.3.5 - 'mod_copy' Command Execution (Metasploit)2015-06-10
exploitdb49908ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)2021-05-26

References only — no downloads or instructions.

Sources