Exploited Vulnerabilities Daily
🌐 English

CVE-2015-3306: ProFTPD ProFTPD

Vendor
ProFTPD
Product
ProFTPD
Vulnerability
ProFTPD Improper Access Control Vulnerability
Date added
Oct 8, 2026
CISA due date (U.S. federal agencies)
Oct 11, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-284

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.08

About this page

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.