CVE-2015-3306 — ProFTPD Improper Access Control Vulnerability

CVE-2015-3306

ProFTPD mod_copy - Unauthenticated Arbitrary File Copy via SITE CPFR/CPTO

What is ProFTPD?

ProFTPD is a long-established open-source FTP server for Unix and Linux, used for file distribution, web hosting upload areas, backup drops, and appliance firmware. It is modular: functionality such as TLS, SQL-backed authentication, and server-side file copying lives in loadable modules. mod_copy is one of those modules. It adds the non-standard SITE CPFR (copy from) and SITE CPTO (copy to) commands so a client can duplicate a file on the server without transferring it down and back up again. ProFTPD typically listens on TCP 21 on hosts that also run a web server, which is exactly the combination this vulnerability needs.

Overview

CVE-2015-3306 is a missing authentication check in mod_copy. The module registered its SITE CPFR and SITE CPTO handlers without requiring that the client be logged in first, so any client that could open a TCP connection to the FTP port could issue them. The result is unauthenticated arbitrary file read and write anywhere the ProFTPD process can reach on the filesystem.

File copying alone is serious enough: an attacker can read /etc/passwd, application configuration files, private keys, or database credentials by copying them into the anonymous download area, and can overwrite files the service user owns. The step to remote code execution is the trick that made this CVE famous. The attacker sends a PHP payload as part of an FTP command, then uses SITE CPFR /proc/self/cmdline followed by SITE CPTO /var/www/html/shell.php to copy the server's own command line, which now contains the payload, into a web-accessible directory. Requesting the file through the web server executes it. The copy and the resulting code run with the privileges of the ProFTPD worker, commonly nobody on a default build.

NVD scores the flaw 10.0 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), with scope changed to reflect that the impact lands on a neighbouring component, the web server. CISA added it to the KEV catalog on 2026-10-08, more than eleven years after the fix, which in practice means long-lived unpatched installations are still being hit.

Affected Versions

Product Vulnerable Fixed
ProFTPD 1.3.5 branch 1.3.5 and earlier builds with mod_copy enabled 1.3.5a
ProFTPD 1.3.6 development branch before 1.3.6rc1 1.3.6rc1
Debian 7 wheezy (proftpd-dfsg) before 1.3.4a-5+deb7u3 1.3.4a-5+deb7u3
Debian 8 jessie (proftpd-dfsg) before 1.3.5-1.1+deb8u1 1.3.5-1.1+deb8u1

Only installations with mod_copy built in and loaded are exploitable. Some distribution packages, Fedora's among them, shipped the module disabled by default. A closely related arbitrary file copy flaw in the same module, CVE-2019-12815, affects versions through 1.3.5b, so 1.3.5a is not a safe long-term resting point.

Technical Details

The CWE assignment is CWE-284, improper access control: the code performs a privileged operation without first checking that the requester is entitled to it. Concretely, mod_copy installed its command handlers in the general command table rather than the post-authentication table, so the FTP state machine dispatched SITE CPFR and SITE CPTO before any USER/PASS exchange had taken place. The upstream fix, merged as commit 35b65aa in pull request 109, adds the authentication requirement and also introduces an Engine directive so administrators can switch the module off in builds where it is compiled in.

Attack characteristics are about as favourable to an attacker as they get: no authentication, no user interaction, low complexity, and no need to chain another vulnerability for file read and write. Reaching code execution does require a second condition, a directory that the ProFTPD user can write to and that a web server or other interpreter will execute from. The full exploit is two FTP commands after a payload-bearing command, which fits comfortably in a mass-scanning script.

Discovery

The flaw was reported by Vadim Melihow in ProFTPD bug 4169 on 2015-04-07. ProFTPD maintainer TJ Saunders (Castaglia) opened and merged the fix the same day. A weaponised exploit by R-73eN appeared on Exploit-DB on 2015-04-21, before the CVE record itself was published on 2015-05-18, and a Metasploit module, exploit/unix/ftp/proftpd_modcopy_exec, followed shortly after. Eric Romang's write-up documented the /proc/self/cmdline technique publicly.

Exploitation Context

Exploitation of this CVE is opportunistic rather than targeted. Reliable public exploits have existed since April 2015 in Metasploit, Exploit-DB, and dozens of standalone scripts, and the vulnerability is a fixture of commodity scanning against port 21. It is a popular route to an initial webshell on shared hosting and on embedded or appliance systems that bundled an old ProFTPD and never updated it.

CISA's catalog entry records known exploitation but names no threat actor, and no public reporting attributes a specific campaign, ransomware family, or botnet to this CVE. CISA marks it as not known to be used in ransomware campaigns. Exposure is hard to count precisely because the FTP banner does not reveal whether mod_copy is loaded, so internet-wide counts of ProFTPD 1.3.5 banners overstate the vulnerable population while still describing a large body of unmaintained hosts.

Remediation

  1. Upgrade ProFTPD to 1.3.5a or 1.3.6rc1 at minimum, and preferably to a currently supported release, since CVE-2019-12815 affects the same module through 1.3.5b.
  2. On distribution packages, apply the vendor update instead of building from source: Debian users need 1.3.4a-5+deb7u3, 1.3.5-1.1+deb8u1, or later, and other distributions shipped equivalent backports.
  3. If you cannot patch immediately, disable mod_copy. Remove it from the build or comment out its LoadModule line, then restart the service and confirm that SITE CPFR returns an error.
  4. Restrict reachability. FTP on port 21 rarely needs to be open to the whole internet; put it behind a firewall allowlist or a VPN.
  5. Separate the FTP service account from web content. If the ProFTPD worker cannot write into any directory that PHP or another interpreter will execute, the file-copy flaw cannot become code execution.
  6. Review logs and the filesystem for compromise. Look for SITE CPFR and SITE CPTO in the FTP transfer log from sessions with no preceding successful login, and for unexpected .php or script files in upload and web directories with timestamps that do not match your deployments.
  7. Federal civilian agencies must remediate by 2026-10-11 under BOD 26-04 and carry out the forensic triage the directive requires.

Key Details

PropertyValue
CVE ID CVE-2015-3306
Vendor / Product ProFTPD — ProFTPD
NVD Published2015-05-18
NVD Last Modified2026-10-08
CVSS 3.1 Score10
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SeverityCRITICAL
CWE CWE-284 find similar ↗
CISA KEV Added2026-10-08
CISA KEV Deadline2026-10-11
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2026-10-11. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

DateEvent
2015-04-07Vadim Melihow reports ProFTPD bug 4169; the fix is committed and merged upstream the same day
2015-04-21Working remote command execution exploit published as Exploit-DB 36803
2015-05-18CVE-2015-3306 record published
2015-05-19Debian publishes DSA-3263-1 with fixed packages
2026-10-08Added to CISA Known Exploited Vulnerabilities catalog
2026-10-11CISA BOD 26-04 remediation deadline