CRITICALCVSS 10Vulnerability
CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Properties
- severity
- CRITICAL
- product
- ProFTPD
- vulnerabilityName
- ProFTPD Improper Access Control Vulnerability
- cvss_score
- 10
- cvss_severity
- CRITICAL
- dueDate
- 2026-10-11
- retrieved_at
- 2026-10-08T19:23:25+00:00
- requiredAction
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
- dateAdded
- 2026-10-08
- score
- 10
- last_source
- NVD
- cve_id
- CVE-2015-3306
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- signal_observed_at
- 2026-10-08T19:23:25+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- vendorProject
- ProFTPD
- published_at
- 2015-05-18T15:59:10.743
- last_modified
- 2026-10-08T18:17:10.857
Related Entities (4)
HAS_WEAKNESS (1)
→[Weakness]Improper Access Control
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
KNOWN_EXPLOITED (1)
→[Source]CISA KEV
Explore deeper with Ninja Signal's threat intelligence graph