CVE-2015-3306
ProFTPD Improper Access Control Vulnerability
10.0
CVSS 3.1
96.8 %
EPSS (current)
2026-10-08
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: ProFTPD / ProFTPD
Published: 2015-05-18 · Due (CISA): 2026-10-11
CWE: CWE-284 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | network/cves/2015/CVE-2015-3306.yaml | ProFTPd - Remote Code Execution | – |
| exploitdb | 36742 | ProFTPd 1.3.5 - File Copy | 2015-04-13 |
| exploitdb | 36803 | ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution | 2015-04-21 |
| metasploit | exploit/unix/ftp/proftpd_modcopy_exec | exploit/unix/ftp/proftpd_modcopy_exec | 2015-04-22 |
| exploitdb | 37262 | ProFTPd 1.3.5 - 'mod_copy' Command Execution (Metasploit) | 2015-06-10 |
| exploitdb | 49908 | ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2) | 2021-05-26 |
References only — no downloads or instructions.