SecPod

Learn Search

Search across all Learn content

← Back to Security Research
ALERT: ProFTPD Server Arbitrary File Copy Vulnerability (CVE-2019-12815)

ALERT: ProFTPD Server Arbitrary File Copy Vulnerability (CVE-2019-12815)

Jul 23, 2019By Shakeel Bhat2 min read

ProFTPd is an open-source, cross-platform FTP server and is one among the most popular FTP servers used in Unix-like environments. It comes pre-installed with many Linux and Unix distributions and is used by a number of popular businesses and websites including SourceForge, Samba and Slackware.

An improper access control vulnerability discovered in ProFTPD, which under certain conditions exploits to execute arbitrary code and cause information disclosure. Identifies the vulnerability as CVE-2019-12815 and resides in ProFTPD’s mod_copy module. Vulnerability management solution is essential here. The mod_copy enables default in most distributions. This allows users to copy files/directories from one place to another on a server without having to transfer the data to the client and back. A patch management tool can remediate this vulnerability.

According to the ProFTPD bug report, the mod_copy module provides two custom commands SITE CPFR and SITE CPTO, which do not follow permission directions specified as per configuration and thus allow remote users to copy a file to the current folder even if they don’t have permission. The vulnerability exploites by unauthorizedly copying an executable file to a location on the server where it executes.

It is important to note that not every FTP server running vExploiting the vulnerable ProFTPD FTP server remotely is not possible in every case. Successful exploitation requires the following conditions:

  • An attacker should be able to authenticate to the ProFTPD server either by a user account or an anonymous account.
  • Enable the mod_copy module.
  • The FTP directory should also be accessible from a web server.

Affected Products:

The vulnerability affects ProFTPD versions 1.3.4 through 1.3.6 (Note: also affects ProFTPd 1.3.6 and does not contain the fix)

Impact:

The flaw may allow remote code execution or information disclosure.

Solution:

According to the ProFTPD bug report, the fix for this vulnerability merges and backported to the version 1.3.6 branch. However, the researcher who reports this bug states in the advisory that the vulnerability wasn’t fixed in version 1.3.6

Workaround:
Please refer to this KB article.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026