ProFTPD SQL Injection Flaw Enables Remote Code Execution
ID: 421666a4-e005-5577-9362-8551c9ff3d41
STIX ID: report--421666a4-e005-5577-9362-8551c9ff3d41
Feed Name: Cyber Press
A critical pre-authentication SQL injection (CVE-2026-42167) in ProFTPD's mod_sql can allow attackers to inject SQL via crafted USER names in logging queries, enabling remote code execution (when the SQL backend runs with excessive privileges), authentication bypass (creation of backdoor users), privilege escalation (setting home to /), and credential exfiltration; the flaw has a CVSSv3 score of 8.1, affects many default deployments and hosting control panels, public proof-of-concepts exist, and ProFTPD 1.3.9a (released 2026-04-27) contains the official fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
