The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Jul 30, 2024 | May 18, 2015 |
| Freebsd | — | Upgrade proftpd | Dec 10, 2025 | May 20, 2015 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | May 18, 2015 |
| Suse | — | Upgrade proftpd-docUpgrade proftpd-sqliteUpgrade proftpd-debuginfoUpgrade proftpd-sqlite-debuginfoUpgrade proftpd-ldapUpgrade proftpd-ldap-debuginfoUpgrade proftpd-langUpgrade proftpd-radius-debuginfoUpgrade proftpd-pgsql-debuginfoUpgrade proftpd-mysqlUpgrade proftpd-pgsqlUpgrade proftpd-debugsourceUpgrade proftpd-develUpgrade proftpd-mysql-debuginfoUpgrade proftpdUpgrade proftpd-radius | Dec 18, 2015 | May 18, 2015 |
| Ubuntu | — | Upgrade proftpd-dfsg | Nov 19, 2024 | May 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub