What is ProFTPD?
ProFTPD is a long-established open-source FTP server for Unix and Linux, used for file distribution, web hosting upload areas, backup drops, and appliance firmware. It is modular: functionality such as TLS, SQL-backed authentication, and server-side file copying lives in loadable modules. mod_copy is one of those modules. It adds the non-standard SITE CPFR (copy from) and SITE CPTO (copy to) commands so a client can duplicate a file on the server without transferring it down and back up again. ProFTPD typically listens on TCP 21 on hosts that also run a web server, which is exactly the combination this vulnerability needs.
Overview
CVE-2015-3306 is a missing authentication check in mod_copy. The module registered its SITE CPFR and SITE CPTO handlers without requiring that the client be logged in first, so any client that could open a TCP connection to the FTP port could issue them. The result is unauthenticated arbitrary file read and write anywhere the ProFTPD process can reach on the filesystem.
File copying alone is serious enough: an attacker can read /etc/passwd, application configuration files, private keys, or database credentials by copying them into the anonymous download area, and can overwrite files the service user owns. The step to remote code execution is the trick that made this CVE famous. The attacker sends a PHP payload as part of an FTP command, then uses SITE CPFR /proc/self/cmdline followed by SITE CPTO /var/www/html/shell.php to copy the server's own command line, which now contains the payload, into a web-accessible directory. Requesting the file through the web server executes it. The copy and the resulting code run with the privileges of the ProFTPD worker, commonly nobody on a default build.
NVD scores the flaw 10.0 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), with scope changed to reflect that the impact lands on a neighbouring component, the web server. CISA added it to the KEV catalog on 2026-10-08, more than eleven years after the fix, which in practice means long-lived unpatched installations are still being hit.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| ProFTPD 1.3.5 branch | 1.3.5 and earlier builds with mod_copy enabled | 1.3.5a |
| ProFTPD 1.3.6 development branch | before 1.3.6rc1 | 1.3.6rc1 |
| Debian 7 wheezy (proftpd-dfsg) | before 1.3.4a-5+deb7u3 | 1.3.4a-5+deb7u3 |
| Debian 8 jessie (proftpd-dfsg) | before 1.3.5-1.1+deb8u1 | 1.3.5-1.1+deb8u1 |
Only installations with mod_copy built in and loaded are exploitable. Some distribution packages, Fedora's among them, shipped the module disabled by default. A closely related arbitrary file copy flaw in the same module, CVE-2019-12815, affects versions through 1.3.5b, so 1.3.5a is not a safe long-term resting point.
Technical Details
The CWE assignment is CWE-284, improper access control: the code performs a privileged operation without first checking that the requester is entitled to it. Concretely, mod_copy installed its command handlers in the general command table rather than the post-authentication table, so the FTP state machine dispatched SITE CPFR and SITE CPTO before any USER/PASS exchange had taken place. The upstream fix, merged as commit 35b65aa in pull request 109, adds the authentication requirement and also introduces an Engine directive so administrators can switch the module off in builds where it is compiled in.
Attack characteristics are about as favourable to an attacker as they get: no authentication, no user interaction, low complexity, and no need to chain another vulnerability for file read and write. Reaching code execution does require a second condition, a directory that the ProFTPD user can write to and that a web server or other interpreter will execute from. The full exploit is two FTP commands after a payload-bearing command, which fits comfortably in a mass-scanning script.
Discovery
The flaw was reported by Vadim Melihow in ProFTPD bug 4169 on 2015-04-07. ProFTPD maintainer TJ Saunders (Castaglia) opened and merged the fix the same day. A weaponised exploit by R-73eN appeared on Exploit-DB on 2015-04-21, before the CVE record itself was published on 2015-05-18, and a Metasploit module, exploit/unix/ftp/proftpd_modcopy_exec, followed shortly after. Eric Romang's write-up documented the /proc/self/cmdline technique publicly.
Exploitation Context
Exploitation of this CVE is opportunistic rather than targeted. Reliable public exploits have existed since April 2015 in Metasploit, Exploit-DB, and dozens of standalone scripts, and the vulnerability is a fixture of commodity scanning against port 21. It is a popular route to an initial webshell on shared hosting and on embedded or appliance systems that bundled an old ProFTPD and never updated it.
CISA's catalog entry records known exploitation but names no threat actor, and no public reporting attributes a specific campaign, ransomware family, or botnet to this CVE. CISA marks it as not known to be used in ransomware campaigns. Exposure is hard to count precisely because the FTP banner does not reveal whether mod_copy is loaded, so internet-wide counts of ProFTPD 1.3.5 banners overstate the vulnerable population while still describing a large body of unmaintained hosts.
Remediation
- Upgrade ProFTPD to 1.3.5a or 1.3.6rc1 at minimum, and preferably to a currently supported release, since CVE-2019-12815 affects the same module through 1.3.5b.
- On distribution packages, apply the vendor update instead of building from source: Debian users need 1.3.4a-5+deb7u3, 1.3.5-1.1+deb8u1, or later, and other distributions shipped equivalent backports.
- If you cannot patch immediately, disable
mod_copy. Remove it from the build or comment out itsLoadModuleline, then restart the service and confirm thatSITE CPFRreturns an error. - Restrict reachability. FTP on port 21 rarely needs to be open to the whole internet; put it behind a firewall allowlist or a VPN.
- Separate the FTP service account from web content. If the ProFTPD worker cannot write into any directory that PHP or another interpreter will execute, the file-copy flaw cannot become code execution.
- Review logs and the filesystem for compromise. Look for
SITE CPFRandSITE CPTOin the FTP transfer log from sessions with no preceding successful login, and for unexpected.phpor script files in upload and web directories with timestamps that do not match your deployments. - Federal civilian agencies must remediate by 2026-10-11 under BOD 26-04 and carry out the forensic triage the directive requires.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2015-3306 |
| Vendor / Product | ProFTPD — ProFTPD |
| NVD Published | 2015-05-18 |
| NVD Last Modified | 2026-10-08 |
| CVSS 3.1 Score | 10 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Severity | CRITICAL |
| CWE | CWE-284 find similar ↗ |
| CISA KEV Added | 2026-10-08 |
| CISA KEV Deadline | 2026-10-11 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2015-04-07 | Vadim Melihow reports ProFTPD bug 4169; the fix is committed and merged upstream the same day |
| 2015-04-21 | Working remote command execution exploit published as Exploit-DB 36803 |
| 2015-05-18 | CVE-2015-3306 record published |
| 2015-05-19 | Debian publishes DSA-3263-1 with fixed packages |
| 2026-10-08 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2026-10-11 | CISA BOD 26-04 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD - CVE-2015-3306 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |
| ProFTPD PR 109 - Bug 4169, Unauthenticated Copying of Files via SITE CPFR/CPTO Allowed by mod_copy | Vendor Advisory |
| Debian DSA-3263-1 - proftpd-dfsg Security Update | Vendor Advisory |
| Rapid7 - ProFTPD 1.3.5 Mod_Copy Command Execution Metasploit Module | Security Research |
| Exploit-DB 36803 - ProFTPd 1.3.5 mod_copy Remote Command Execution | Exploit/PoC |
| Eric Romang - CVE-2015-3306 ProFTPD 1.3.5 Mod_Copy Command Execution | Security Research |
| Debian Security Tracker - CVE-2015-3306 | Vulnerability Database |