CVE-2006-5815

Exp

Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."

Published: 2006-11-08 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2006-5815 is rated High Exploit Risk (90/100): CVSS Critical severity, with high exploitation likelihood (EPSS 74.25%, 99th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2006-5815

EDB-ID Source Kind Published Link
16852 exploit_db edb 2011-01-09 Exploit-DB ↗
2856 exploit_db edb 2006-11-27 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2006-5815

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-21 74.08% 74.25% +0.18%
2 2026-06-15 74.73% 74.08% -0.66%
3 2026-05-18 74.73%

Full EPSS history (29 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2006-5815

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2006-5815

OS Trackers for CVE-2006-5815

vendor priority summary link
alpine CVE-2006-5815: no source package rows; 0 state rows across 0 repos (none); fixed 0, open 0. https://security.alpinelinux.org/vuln/CVE-2006-5815
debian high CVE-2006-5815 high priority: Debian including 1 source packages (proftpd-dfsg), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2006-5815
gentoo high CVE-2006-5815: 1 GLSA(s) (200611-26), 1 atom(s) (net-ftp/proftpd); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2006-5815
ubuntu medium CVE-2006-5815 medium priority: Ubuntu including 2 source packages (proftpd, proftpd-dfsg), 8 status rows across 4 suites (dapper, edgy, feisty, upstream): DNE 3, released 3, needs-triage 2. https://ubuntu.com/security/CVE-2006-5815

NVD evaluator notes for CVE-2006-5815

Comment: An off-by-one string manipulation flaw in ProFTPD's sreplace() function exists allowing a remote attacker to execute arbitrary code.

Affected software / configurations for CVE-2006-5815

Vendor Product Version Raw CPE
proftpd_project proftpd <= 1.3.0 cpe:2.3:a:proftpd_project:proftpd:*:*:*:*:*:*:*:*

References for CVE-2006-5815

URL Tags
http://bugs.proftpd.org/show_bug.cgi?id=2858
http://gleg.net/vulndisco_meta.shtml
http://secunia.com/advisories/22803 Vendor Advisory
http://secunia.com/advisories/22821 Vendor Advisory
http://secunia.com/advisories/23000 Vendor Advisory
http://secunia.com/advisories/23069 Vendor Advisory
http://secunia.com/advisories/23125 Vendor Advisory
http://secunia.com/advisories/23174 Vendor Advisory
http://secunia.com/advisories/23179 Vendor Advisory
http://secunia.com/advisories/23184 Vendor Advisory
http://secunia.com/advisories/23207 Vendor Advisory
http://securitytracker.com/id?1017167
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.502491
http://www.debian.org/security/2006/dsa-1222
http://www.gentoo.org/security/en/glsa/glsa-200611-26.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:217
http://www.mandriva.com/security/advisories?name=MDKSA-2006:217-1
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.035-proftpd.html
http://www.securityfocus.com/archive/1/452760/100/200/threaded
http://www.securityfocus.com/bid/20992
http://www.trustix.org/errata/2006/0066/
http://www.trustix.org/errata/2006/0070
http://www.vupen.com/english/advisories/2006/4451 Vendor Advisory
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=214820
https://exchange.xforce.ibmcloud.com/vulnerabilities/30147
cvelogic Threat Intelligence