The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3306