XHack Logo
XHack
Products
Services
Compliance
Pricing
Resources
Company
Sign upLogin
XHack Logo
XHackOffensive Security

Certified offensive security team delivering penetration testing evidence written for your auditor.

OSCP+OSCPC-AI/MLPenCASA
support@xhack.io

24/7 SOC Operations

XHack Status
Under attack? Get help now
Services
  • VAPT Services
  • Red Teaming
  • SOC Services
  • Threat Intelligence
  • Incident Response
  • Managed Testing
Pricing
  • Platform Plans
  • Services Pricing
Compliance
  • SOC 2
  • PCI DSS
  • ISO 27001
  • GDPR
  • HIPAA
  • ISO 42001
  • AI Maturity Assessment
  • TX-RAMP
  • NBFC / SECP
  • All Frameworks
Products
  • Vulnerability Assessment
  • GitGuard
  • AI Probe
  • SOC Dashboard
  • AI Agent
  • Cloud Investigation
Comparison
  • XBOW vs XHack
  • Horizon3 vs XHack
  • Strix vs XHack
  • Pentera vs XHack
Resources
  • Platform Tour
  • All Features
  • Install the Agent
  • XHack AI
  • Documentation
  • Blog
  • Case Studies
  • Documents
  • FAQ
Company
  • About Us
  • Our Team
  • Certifications
  • Security and Trust
  • VAPT Explained
  • Contact

© 2026 XHack. All rights reserved.

Security & TrustVulnerability DisclosurePrivacy PolicyTerms of ServiceRefund Policy
Blog/News

CVE-2015-3306: The Critical ProFTPD Bug From 2015 That CISA Just Flagged

XHack

XHack

Author

October 10, 2026

10 min read

CVE-2015-3306: The Critical ProFTPD Bug From 2015 That CISA Just Flagged

Table of contents

16

What CVE-2015-3306 Is, According to the Sources

What CISA Added, and What It Did Not Say

Which Versions Are Affected by CVE-2015-3306

How the mod_copy Module Behind CVE-2015-3306 Works

Public Exploit Code Exists for CVE-2015-3306

Checking Your Own Servers for CVE-2015-3306

The Forensic Step Comes Before the CVE-2015-3306 Fix

How to Fix CVE-2015-3306

FAQ: CVE-2015-3306 Questions Answered

What is CVE-2015-3306?

Is CVE-2015-3306 being exploited?

Which version fixes CVE-2015-3306?

Can I just disable mod_copy for CVE-2015-3306?

How do I know if CVE-2015-3306 was used against me?

How XHack Helps Find Old Bugs Like CVE-2015-3306

The Bottom Line on CVE-2015-3306

Read this in 30 seconds: CVE-2015-3306 is an eleven-year-old flaw in the mod_copy module of ProFTPD, a widely used FTP server. An unauthenticated client can copy and move files on the server through two FTP commands. CISA added it to its Known Exploited Vulnerabilities catalog on October 8, 2026, with a deadline of October 11 and a forensic-triage flag.

  • No login is needed. Debian’s advisory says unauthenticated users could copy files around on the server, and NVD lists the flaw as CWE-284, improper access control.
  • The bug is old, the flag is new. Debian published its fix on May 19, 2015. CISA’s catalog entry is dated October 8, 2026, and the catalog does not say why it was added now.
  • Check the version, then the module. Debian’s fixed package versions are listed below. If you cannot patch, unload mod_copy and confirm it is gone.
  • Preserve logs before you change anything. CISA flags this entry for forensic triage, which means evidence should be kept before the fix.
  • Public exploit code exists. NVD’s references point to published proof-of-concept code and a Metasploit module. Assume the bug is easy to reach if the module is loaded.

The most dangerous bugs are often the ones everyone assumed were fixed years ago, still running on a server nobody has looked at since.

ProFTPD is an FTP server that many Linux distributions package, and FTP servers are often installed once and then forgotten. That is the context for CVE-2015-3306, and it explains why an eleven-year-old bug can still be a live problem on a real network.

This article covers what the bug is, how the sources describe it, which versions are affected, what the sources disagree on, how to check your own servers, and what to do before you change anything.

Debian fixed package versions for CVE-2015-3306 across wheezy, jessie, stretch and sid
CVE-2015-3306: fixed Debian packages, release by release

What CVE-2015-3306 Is, According to the Sources

The NVD description says the mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write arbitrary files through the site cpfr and site cpto commands. Those are FTP commands that copy or move a file from one path to another. The bug is that the module does not check who is asking.

Debian’s security advisory, DSA-3263-1, dated May 19, 2015, gives a slightly different description. It says that Vadim Melihow reported that the mod_copy module “allowed unauthenticated users to copy files around” on the server, and that this could possibly lead to arbitrary code execution. The advisory does not say which commands were involved, and it does not say whether the flaw allows reads, writes or both. We have not verified those details against ProFTPD’s own advisory, because ProFTPD’s site refused our connection when we tried.

The scoring is high. NVD‘s own CVSS 2 score is 10.0, with the vector AV:N/AC:L/Au:N/C:C/I:C/A:C. NVD also lists a CVSS 3.1 score of 10.0 from a secondary source, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Both scores describe the same thing: no authentication, low complexity, and high impact across confidentiality, integrity and availability.

What CISA Added, and What It Did Not Say

CISA’s catalog entry for CVE-2015-3306 is dated October 8, 2026. It carries a due date of October 11, a forensic-triage flag, and “Unknown” for known ransomware use. The entry’s notes point to the ProFTPD site and to the Debian and openSUSE advisories from 2015.

The catalog does not say why CISA added a bug from 2015 now. We did not find a CISA statement, a vendor note or a published exploitation report that explains the timing. Our searches also returned summaries that said the bug was not in the catalog. Those summaries were secondary, and they contradicted the CISA catalog file itself, so we used the file. We recommend you check it directly as well.

Which Versions Are Affected by CVE-2015-3306

NVD lists ProFTPD 1.3.5 as the affected product. Debian’s advisory gives the fixed package versions for its own releases:

Debian releaseFixed package version
Oldstable (wheezy)proftpd-dfsg 1.3.4a-5+deb7u3
Stable (jessie)proftpd-dfsg 1.3.5-1.1+deb8u1
Testing and unstable (stretch, sid)proftpd-dfsg 1.3.5-2

The upstream fix version is harder to pin down. Some secondary sources say ProFTPD 1.3.5a addressed this issue. An openSUSE update also reportedly moved to 1.3.5a for it. We could not open ProFTPD’s own release notes to confirm that, so treat the upstream version as unverified. The safe step is to use your distribution’s patched package, since those are the versions the advisory names.

How the mod_copy Module Behind CVE-2015-3306 Works

mod_copy adds FTP commands that copy and move files on the server. The bug is that an unauthenticated client can use them. We will not walk through the command sequence. The description above is enough for a defender to know what to look for, and that the risk comes from a server-side file operation that was reachable without a login.

The reason this matters more than a typical file-read bug is what file access can lead to. Debian’s advisory says the flaw could possibly lead to code execution, and public proof-of-concept code is widely available. An attacker who can place or move files into a location the server executes may be able to run code. Whether that is possible on a given server depends on its configuration, so do not assume a file-copy bug is harmless on the grounds that it is “only” read or write.

Public Exploit Code Exists for CVE-2015-3306

NVD’s reference list includes several public exploits, including two Exploit-DB entries and a Rapid7 Metasploit module for ProFTPD mod_copy command execution. Those references are the reason we say public exploit code exists. We are not going to walk through how any of them work. What matters for defenders is that the bug is well documented, and a working module has been available for years, so a version check alone is not a safe answer.

Checking Your Own Servers for CVE-2015-3306

Start with inventory. Find every host that runs ProFTPD, including containers and appliances, because the version in a package list is not always the version running.

On a Debian-family host, you can check the installed package version against the fixed versions above:

# Show the installed ProFTPD package version
dpkg -l | grep -i proftpd

# Check whether mod_copy is loaded in the active configuration
grep -ri "mod_copy" /etc/proftpd/

Next, look for signs of use. Search your FTP logs for the CPFR and CPTO commands, which is our suggestion rather than a published indicator. Log locations vary by distribution and configuration, so find yours first.

# Search FTP logs for copy-related commands (adjust the path for your system)
grep -i "CPFR\|CPTO" /var/log/proftpd/*.log

Any hit needs a manual review. Legitimate administrators rarely use these commands, so an unexpected hit is worth taking seriously.

Finally, look at the file system where the server runs. Check for recently created or moved files in the FTP root and in any directory the server executes, and compare them against what you expect.

The Forensic Step Comes Before the CVE-2015-3306 Fix

CISA’s forensic-triage flag means you should preserve evidence before you patch or rebuild. A patch can overwrite the traces you need.

Before you change anything:

  1. Copy the FTP and system logs for the period you can still reach.
  2. Record the running version and the loaded modules.
  3. Save a copy of the configuration and any suspicious files.
  4. Only then patch or unload the module.

If the logs show copy commands you cannot explain, escalate and treat the server as possibly compromised.

How to Fix CVE-2015-3306

Work through these in order:

  1. Install your distribution’s patched package. Use the fixed versions in the table above for Debian releases, or the patched package from your distribution’s own advisory.
  2. If you cannot patch today, unload mod_copy. Commenting out the module’s load line in the ProFTPD configuration and restarting the service removes the vulnerable commands. Secondary guidance describes this step, so confirm it on a test system first.
  3. Confirm the module is gone. After the restart, check the loaded modules and try the copy commands from a test account, not an external host you do not control.
  4. Review the logs again after the fix, looking for copy commands that continue after the change.

FAQ: CVE-2015-3306 Questions Answered

What is CVE-2015-3306?

It is an improper access control flaw in the mod_copy module of ProFTPD. An unauthenticated remote client can copy and move files on the server through the site cpfr and site cpto commands. NVD classifies it as CWE-284.

Is CVE-2015-3306 being exploited?

CISA’s Known Exploited Vulnerabilities catalog lists it, with an entry dated October 8, 2026, a deadline of October 11 and a forensic-triage flag. The catalog does not say why it was added now.

Which version fixes CVE-2015-3306?

For Debian, the fixed packages are proftpd-dfsg 1.3.4a-5+deb7u3 on wheezy, 1.3.5-1.1+deb8u1 on jessie, and 1.3.5-2 on stretch and sid. The upstream version is unverified in our sources, so use your distribution’s patched package.

Can I just disable mod_copy for CVE-2015-3306?

Yes, if your deployment does not need the module. Unloading it removes the vulnerable commands. Confirm the change on a test system, and check your version’s documentation for the exact directive, since some secondary sources describe a newer configuration option that older builds may not have.

How do I know if CVE-2015-3306 was used against me?

Preserve your logs, then search for CPFR and CPTO commands and review every hit. Also check the server’s file system for recently created or moved files in the FTP root and in directories the server executes. A clean result does not prove the server is clean, especially if your logs have rotated.

How XHack Helps Find Old Bugs Like CVE-2015-3306

Old network services are often found by inventory rather than by a new exploit. Knowing which hosts run which software and versions, and which ones should not be reachable, is most of the work.

Our AI VAPT services combine automated and human-led testing against exposed services, and the inventory and exposure review above is part of that work. A pentest report documents what was tested and what was found. It does not certify that a host is free of this bug, and it does not replace the patch.

If you test your own systems with XHack AI, its findings carry a severity rating, a CWE, references, proof and reproduction steps. Review each one yourself before you act on it, because an automated tool can be wrong in either direction.

The Bottom Line on CVE-2015-3306

CVE-2015-3306 is an eleven-year-old ProFTPD flaw that lets an unauthenticated client copy and move files on the server. CISA has now listed it as exploited, with an October 11 deadline and a forensic-triage flag, and public exploit code exists.

Inventory your ProFTPD hosts, preserve the logs, and then install the patched package or unload mod_copy. The fix is short. The hard part is finding every server still running the old version.


Categories

News

Next

Bug Bounty Methodology: The Honest 6-Phase Recon-to-Report Workflow

On this page

What CVE-2015-3306 Is, According to the Sources

What CISA Added, and What It Did Not Say

Which Versions Are Affected by CVE-2015-3306

How the mod_copy Module Behind CVE-2015-3306 Works

Public Exploit Code Exists for CVE-2015-3306

Checking Your Own Servers for CVE-2015-3306

The Forensic Step Comes Before the CVE-2015-3306 Fix

How to Fix CVE-2015-3306

FAQ: CVE-2015-3306 Questions Answered

What is CVE-2015-3306?

Is CVE-2015-3306 being exploited?

Which version fixes CVE-2015-3306?

Can I just disable mod_copy for CVE-2015-3306?

How do I know if CVE-2015-3306 was used against me?

How XHack Helps Find Old Bugs Like CVE-2015-3306

The Bottom Line on CVE-2015-3306

Related articles

Continue reading

CVE-2016-3081: Why CISA Just Flagged This Ten-Year-Old Struts Exploit

News

CVE-2016-3081: Why CISA Just Flagged This Ten-Year-Old Struts Exploit

CVE-2016-3081 is an Apache Struts command-injection bug CISA just flagged as exploited. Affected versions, the 2.3.19 co...

Read article
CVE-2026-76461: The Critical Cisco Email Gateway Bug Triggered by One Email

News

CVE-2026-76461: The Critical Cisco Email Gateway Bug Triggered by One Email

CVE-2026-76461 is a CVSS 9.8 SQL injection in Cisco Secure Email Gateway, exploited in the wild. Affected builds, fixes,...

Read article
CVE-2026-93616: The Critical Check Point Management Server Zero-Day

News

CVE-2026-93616: The Critical Check Point Management Server Zero-Day

CVE-2026-93616 is a CVSS 9.8 pre-auth zero-day in Check Point Security Management, exploited since July 23. Affected ver...

Read article