CVE-2015-3306: ProFTPD ProFTPD
- Vendor
- ProFTPD
- Product
- ProFTPD
- Vulnerability
- ProFTPD Improper Access Control Vulnerability
- Date added
- Oct 8, 2026
- CISA due date (U.S. federal agencies)
- Oct 11, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-284
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.08
About this page
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.