> An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication > allows users without write permissions to copy any file on the FTP server. > mod_copy is supplied in the default installation of ProFTPd and is enabled by default in most distributions (e.g. Debian).