What happened
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Affected versions
n/a: n/a Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
www.exploit-db.comNVD reference2015-05-18Verifiedwww.exploit-db.comNVD reference2015-05-18VerifiedExploit-DB 37262ProFTPd 1.3.5 - 'mod_copy' Command Execution (Metasploit)Metasploit2015-06-10VerifiedExploit-DB 36803ProFTPd 1.3.5 - 'mod_copy' Remote Command ExecutionR-73eN2015-04-21VerifiedExploit-DB 49908ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)Shellbr3ak2021-05-26VerifiedExploit-DB 36742ProFTPd 1.3.5 - File Copyanonymous2015-04-13VerifiedSploitusPre-auth arbitrary file copy in ProFTPD mod_copy via CVE-2015-3306.diegslva2026-09-07T20:37:03Candidatediegslva/cve-2015-3306-labPre-auth arbitrary file copy in ProFTPD mod_copy via CVE-2015-3306.diegslva2026-09-07T20:37:03CandidateSource timeline
Discovered through Exploit-DBView source ↗
CVE record published by NVDView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.