logo

ProFTPD’s SQL Injection Vulnerability Enables Remote Code Execution Attacks

ID: 0dd57dc0-fc5d-5bef-b349-72899800728a

STIX ID: report--0dd57dc0-fc5d-5bef-b349-72899800728a

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Abinaya

...
...

**Executive summary:** A critical SQL injection vulnerability (CVE-2026-42167, CVSS 8.1) in ProFTPD's mod_sql module enables attackers to bypass sanitization of specially crafted usernames and potentially achieve authentication bypass, insert backdoor users, perform blind data extraction, or obtain remote code execution via PostgreSQL's COPY TO PROGRAM; administrators are advised to upgrade to ProFTPD 1.3.9a, disable mod_sql logging if a patch cannot be applied, and monitor FTP and database activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.