CVE-2015-3306
HIGH 10.0EPSS 96.8%
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 96.75% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-284
- Published
- 2015-05-18
- Updated
- 2024-08-06
Proof-of-concept exploits (20)
- http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.html
- http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_exec
- 0xm4ud/ProFTPD_CVE-2015-33061★ · 2021-06-07
- JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution0★ · 2024-04-18
- RodrigoDominguezJimenez/exploitsRDJ0★ · 2024-11-20
- Sampad-Adhikary/qwc4f0★ · 2024-09-23
- Z3R0-0x30/CVE-2015-33060★ · 2025-05-14
- ardiadrianadri/js-exploits1★ · 2026-02-25
- cd6629/CVE-2015-3306-Python-PoC1★ · 2020-12-24
- cdedmondson/Modified-CVE-2015-3306-Exploit0★ · 2020-05-15
- cved-sources/cve-2015-33060★ · 2021-04-15
- davidtavarez/CVE-2015-33061★ · 2017-07-29
- donmedfor/CVE-2015-33060★ · 2025-08-23
- hackarada/cve-2015-33060★ · 2023-09-20
- jptr218/proftpd_bypass1★ · 2021-08-21
- m4udSec/ProFTPD_CVE-2015-33061★ · 2021-06-07
- shk0x/cpx_proftpd1★ · 2015-04-22
- t0kx/exploit-CVE-2015-3306151★ · 2018-04-07
- Z3R0space/CVE-2015-3306
- xyk0x/cpx_proftpd
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/49908
- https://www.exploit-db.com/exploits/37262
- https://www.exploit-db.com/exploits/36742
- https://www.exploit-db.com/exploits/36803