The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade proftpd-dfsg | Jul 30, 2024 | May 18, 2015 |
| Freebsd | — | Upgrade proftpd | Dec 10, 2025 | May 20, 2015 |
| Proftp Proftpd | — | Update ProFTP ProFTPd to the latest version | Nov 6, 2025 | May 18, 2015 |
| Suse | — | Upgrade proftpd-pgsqlUpgrade proftpdUpgrade proftpd-mysql-debuginfoUpgrade proftpd-debugsourceUpgrade proftpd-mysqlUpgrade proftpd-develUpgrade proftpd-radiusUpgrade proftpd-sqliteUpgrade proftpd-sqlite-debuginfoUpgrade proftpd-ldapUpgrade proftpd-ldap-debuginfoUpgrade proftpd-pgsql-debuginfoUpgrade proftpd-docUpgrade proftpd-debuginfoUpgrade proftpd-radius-debuginfoUpgrade proftpd-lang | Dec 18, 2015 | May 18, 2015 |
| Ubuntu | — | Upgrade proftpd-dfsg | Nov 19, 2024 | May 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub