ProFTPD’s SQL Injection Vulnerability Enables Remote Code Execution Attacks
ID: 0dd57dc0-fc5d-5bef-b349-72899800728a
STIX ID: report--0dd57dc0-fc5d-5bef-b349-72899800728a
Feed Name: cybersecurityNews.com
**Executive summary:** A critical SQL injection vulnerability (CVE-2026-42167, CVSS 8.1) in ProFTPD's mod_sql module enables attackers to bypass sanitization of specially crafted usernames and potentially achieve authentication bypass, insert backdoor users, perform blind data extraction, or obtain remote code execution via PostgreSQL's COPY TO PROGRAM; administrators are advised to upgrade to ProFTPD 1.3.9a, disable mod_sql logging if a patch cannot be applied, and monitor FTP and database activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
