CVE-2015-3306: ProFTPD ProFTPD
CISA (English)
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
- ベンダー
- ProFTPD
- 製品
- ProFTPD
- 脆弱性
- ProFTPD Improper Access Control Vulnerability
- 追加日
- 2026/10/08
- CISA対応期限(米国連邦機関向け)
- 2026/10/11
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-284
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.08
このページについて
ProFTPD には、リモート攻撃者がサイト cpfr およびサイト cpto コマンドを介して任意のファイルを読み書きできるようにする不適切なアクセス制御脆弱性が含まれています。