CVE-2015-3306 is a critical vulnerability in the mod_copy module of ProFTPD 1.3.5, which allows remote, unauthenticated attackers to read from and write to arbitrary files on the server using the SITE CPFR and SITE CPTO FTP commands. This flaw enables attackers to copy sensitive files (e.g., /etc/passwd) or inject malicious scripts into web-accessible directories, leading to potential privilege escalation or remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This six-file repository is a reproducible educational lab and Python proof-of-concept for CVE-2015-3306 in ProFTPD's mod_copy module. The primary entry point, exploit.py, uses raw Python sockets to connect to a hard-coded local FTP service at 127.0.0.1:2121. It sends SITE CPFR and SITE CPTO before USER/PASS, exploiting the missing authentication check in vulnerable mod_copy handlers to copy /etc/segredo.txt into /home/ftp under a nanosecond-derived unique filename. It subsequently logs in as the configured anonymous FTP user, uses PASV and RETR to exfiltrate the copied content, handles the FTP 150/226 transfer state sequence, prints the recovered data, and attempts DELE cleanup. Dockerfile builds ProFTPD 1.3.5 with mod_copy from source and provisions the secret source file; proftpd.conf enables anonymous access and constrains passive ports to 30000-30010. patch.diff documents the upstream remediation: authentication checks for CPFR/CPTO plus a CopyEngine control directive. This is functional exploit code rather than a detector, but its target, source path, destination, and exfiltration credentials are basic hard-coded lab defaults.
Repository contains a single Python exploit script and a README. The exploit targets CVE-2015-3306 in ProFTPd 1.3.5 with mod_copy enabled. It opens a raw TCP socket to the target FTP service on port 21 and issues `SITE CPFR <path>` followed by `SITE CPTO <path>` to copy an arbitrary file on the target filesystem to an attacker-chosen location (commonly copying an SSH private key into a web/NFS-accessible directory such as /var/tmp). After deploying the copy operation, the script runs local OS commands to create `/mnt/testdir` and attempts to mount `<target>:/var` to `/mnt/testdir` (suggesting the intended lab scenario includes an NFS export of /var), enabling the attacker to retrieve the copied file. The script is operational but environment-specific (assumes sudo access for mount and an NFS-exported /var) and does not implement robust error handling or a full RCE payload despite the header claiming 'Remote Command Execution'.
This repository contains a Python exploit script (exploit.py) and a README.md. The exploit targets ProFTPd 1.3.5 servers with the 'mod_copy' module enabled (CVE-2015-3306). The script connects to the target's FTP service on port 21, issues FTP commands to copy the file /secret.txt to the web server directory (/var/www/html/secret.txt), and then checks via HTTP if the file is accessible. The exploit demonstrates remote file copy and disclosure, allowing an attacker to retrieve sensitive files from the target system. The code is a proof-of-concept and requires the attacker to specify the target IP address as a command-line argument.
This repository provides a Python proof-of-concept exploit for CVE-2015-3306, a directory traversal vulnerability in ProFTPD 1.3.5b and earlier. The main file, 'exploit-ftp.py', connects to a target FTP server and abuses the 'SITE CPFR/CPTO' commands to copy a PHP webshell ('backdoor.php') into a specified webroot directory. Once deployed, the backdoor allows arbitrary shell command execution via HTTP requests to the webshell. The exploit requires the attacker to specify the target host, FTP port, webroot path, and the command to execute. The repository includes a README with usage instructions and a license file. The exploit is operational, providing a working payload and clear instructions for use against vulnerable ProFTPD installations.
This repository contains a single Metasploit module (modules/exploits/unix/ftp/proftpd_modcopy_exec.rb) targeting ProFTPD 1.3.5 servers with the mod_copy module enabled (CVE-2015-3306). The exploit leverages unauthenticated SITE CPFR/CPTO FTP commands to copy arbitrary files on the server, allowing an attacker to write a PHP webshell into the web root directory. The module then triggers the webshell via HTTP to execute arbitrary commands, ultimately running a Metasploit payload. The exploit requires both FTP and HTTP access to the target, and the web root must be writable by the ProFTPD process. The code is operational and provides remote code execution as the web server user. The main endpoints involved are the FTP (port 21), HTTP (port 80), and file paths such as /proc/self/cmdline, /tmp, and /var/www.
This repository provides a working exploit for CVE-2015-3306, a remote command execution vulnerability in ProFTPD 1.3.5 with the mod_copy module enabled. The repository includes a Dockerfile to build a vulnerable environment (ProFTPD 1.3.5 with mod_copy and Apache), a Python exploit script (exploit.py), and a shell script (main.sh) to start the services. The exploit works by abusing the 'site cpfr' and 'site cpto' FTP commands to copy a PHP payload into the web server's root directory, resulting in a webshell (backdoor.php) accessible via HTTP. The exploit.py script automates this process, connecting to the FTP service, issuing the necessary commands, and then providing the user with access to the webshell for arbitrary command execution. The README.md provides clear instructions for setting up the environment and running the exploit. The main attack vector is network-based, targeting the FTP service on port 21 and resulting in a webshell accessible on port 80. The exploit is operational and provides a real, working payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.