
Table of contents
16
Read this in 30 seconds: CVE-2015-3306 is an eleven-year-old flaw in the mod_copy module of ProFTPD, a widely used FTP server. An unauthenticated client can copy and move files on the server through two FTP commands. CISA added it to its Known Exploited Vulnerabilities catalog on October 8, 2026, with a deadline of October 11 and a forensic-triage flag.
- No login is needed. Debian’s advisory says unauthenticated users could copy files around on the server, and NVD lists the flaw as CWE-284, improper access control.
- The bug is old, the flag is new. Debian published its fix on May 19, 2015. CISA’s catalog entry is dated October 8, 2026, and the catalog does not say why it was added now.
- Check the version, then the module. Debian’s fixed package versions are listed below. If you cannot patch, unload mod_copy and confirm it is gone.
- Preserve logs before you change anything. CISA flags this entry for forensic triage, which means evidence should be kept before the fix.
- Public exploit code exists. NVD’s references point to published proof-of-concept code and a Metasploit module. Assume the bug is easy to reach if the module is loaded.
The most dangerous bugs are often the ones everyone assumed were fixed years ago, still running on a server nobody has looked at since.
ProFTPD is an FTP server that many Linux distributions package, and FTP servers are often installed once and then forgotten. That is the context for CVE-2015-3306, and it explains why an eleven-year-old bug can still be a live problem on a real network.
This article covers what the bug is, how the sources describe it, which versions are affected, what the sources disagree on, how to check your own servers, and what to do before you change anything.

The NVD description says the mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write arbitrary files through the site cpfr and site cpto commands. Those are FTP commands that copy or move a file from one path to another. The bug is that the module does not check who is asking.
Debian’s security advisory, DSA-3263-1, dated May 19, 2015, gives a slightly different description. It says that Vadim Melihow reported that the mod_copy module “allowed unauthenticated users to copy files around” on the server, and that this could possibly lead to arbitrary code execution. The advisory does not say which commands were involved, and it does not say whether the flaw allows reads, writes or both. We have not verified those details against ProFTPD’s own advisory, because ProFTPD’s site refused our connection when we tried.
The scoring is high. NVD‘s own CVSS 2 score is 10.0, with the vector AV:N/AC:L/Au:N/C:C/I:C/A:C. NVD also lists a CVSS 3.1 score of 10.0 from a secondary source, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Both scores describe the same thing: no authentication, low complexity, and high impact across confidentiality, integrity and availability.
CISA’s catalog entry for CVE-2015-3306 is dated October 8, 2026. It carries a due date of October 11, a forensic-triage flag, and “Unknown” for known ransomware use. The entry’s notes point to the ProFTPD site and to the Debian and openSUSE advisories from 2015.
The catalog does not say why CISA added a bug from 2015 now. We did not find a CISA statement, a vendor note or a published exploitation report that explains the timing. Our searches also returned summaries that said the bug was not in the catalog. Those summaries were secondary, and they contradicted the CISA catalog file itself, so we used the file. We recommend you check it directly as well.
NVD lists ProFTPD 1.3.5 as the affected product. Debian’s advisory gives the fixed package versions for its own releases:
| Debian release | Fixed package version |
|---|---|
| Oldstable (wheezy) | proftpd-dfsg 1.3.4a-5+deb7u3 |
| Stable (jessie) | proftpd-dfsg 1.3.5-1.1+deb8u1 |
| Testing and unstable (stretch, sid) | proftpd-dfsg 1.3.5-2 |
The upstream fix version is harder to pin down. Some secondary sources say ProFTPD 1.3.5a addressed this issue. An openSUSE update also reportedly moved to 1.3.5a for it. We could not open ProFTPD’s own release notes to confirm that, so treat the upstream version as unverified. The safe step is to use your distribution’s patched package, since those are the versions the advisory names.
mod_copy adds FTP commands that copy and move files on the server. The bug is that an unauthenticated client can use them. We will not walk through the command sequence. The description above is enough for a defender to know what to look for, and that the risk comes from a server-side file operation that was reachable without a login.
The reason this matters more than a typical file-read bug is what file access can lead to. Debian’s advisory says the flaw could possibly lead to code execution, and public proof-of-concept code is widely available. An attacker who can place or move files into a location the server executes may be able to run code. Whether that is possible on a given server depends on its configuration, so do not assume a file-copy bug is harmless on the grounds that it is “only” read or write.
NVD’s reference list includes several public exploits, including two Exploit-DB entries and a Rapid7 Metasploit module for ProFTPD mod_copy command execution. Those references are the reason we say public exploit code exists. We are not going to walk through how any of them work. What matters for defenders is that the bug is well documented, and a working module has been available for years, so a version check alone is not a safe answer.
Start with inventory. Find every host that runs ProFTPD, including containers and appliances, because the version in a package list is not always the version running.
On a Debian-family host, you can check the installed package version against the fixed versions above:
# Show the installed ProFTPD package version
dpkg -l | grep -i proftpd
# Check whether mod_copy is loaded in the active configuration
grep -ri "mod_copy" /etc/proftpd/
Next, look for signs of use. Search your FTP logs for the CPFR and CPTO commands, which is our suggestion rather than a published indicator. Log locations vary by distribution and configuration, so find yours first.
# Search FTP logs for copy-related commands (adjust the path for your system)
grep -i "CPFR\|CPTO" /var/log/proftpd/*.log
Any hit needs a manual review. Legitimate administrators rarely use these commands, so an unexpected hit is worth taking seriously.
Finally, look at the file system where the server runs. Check for recently created or moved files in the FTP root and in any directory the server executes, and compare them against what you expect.
CISA’s forensic-triage flag means you should preserve evidence before you patch or rebuild. A patch can overwrite the traces you need.
Before you change anything:
If the logs show copy commands you cannot explain, escalate and treat the server as possibly compromised.
Work through these in order:
It is an improper access control flaw in the mod_copy module of ProFTPD. An unauthenticated remote client can copy and move files on the server through the site cpfr and site cpto commands. NVD classifies it as CWE-284.
CISA’s Known Exploited Vulnerabilities catalog lists it, with an entry dated October 8, 2026, a deadline of October 11 and a forensic-triage flag. The catalog does not say why it was added now.
For Debian, the fixed packages are proftpd-dfsg 1.3.4a-5+deb7u3 on wheezy, 1.3.5-1.1+deb8u1 on jessie, and 1.3.5-2 on stretch and sid. The upstream version is unverified in our sources, so use your distribution’s patched package.
Yes, if your deployment does not need the module. Unloading it removes the vulnerable commands. Confirm the change on a test system, and check your version’s documentation for the exact directive, since some secondary sources describe a newer configuration option that older builds may not have.
Preserve your logs, then search for CPFR and CPTO commands and review every hit. Also check the server’s file system for recently created or moved files in the FTP root and in directories the server executes. A clean result does not prove the server is clean, especially if your logs have rotated.
Old network services are often found by inventory rather than by a new exploit. Knowing which hosts run which software and versions, and which ones should not be reachable, is most of the work.
Our AI VAPT services combine automated and human-led testing against exposed services, and the inventory and exposure review above is part of that work. A pentest report documents what was tested and what was found. It does not certify that a host is free of this bug, and it does not replace the patch.
If you test your own systems with XHack AI, its findings carry a severity rating, a CWE, references, proof and reproduction steps. Review each one yourself before you act on it, because an automated tool can be wrong in either direction.
CVE-2015-3306 is an eleven-year-old ProFTPD flaw that lets an unauthenticated client copy and move files on the server. CISA has now listed it as exploited, with an October 11 deadline and a forensic-triage flag, and public exploit code exists.
Inventory your ProFTPD hosts, preserve the logs, and then install the patched package or unload mod_copy. The fix is short. The hard part is finding every server still running the old version.
Categories
Related articles