CVE-2015-3306

Critical10.0 Published on May 18, 2015

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

CVSS score10.0 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness type (CWE)CWE-284, CWE-284
Vendorsproftpd

Affected products

VendorsProductVersions
proftpdproftpd1.3.5

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database