ProFTPD SQL Injection Flaw Opens Door To Remote Code Execution Attacks
ID: efb1d2f9-ae3b-5e11-9371-a3b7e165425d
STIX ID: report--efb1d2f9-ae3b-5e11-9371-a3b7e165425d
Feed Name: GBHackers
ProFTPD's mod_sql module contains a serious SQL injection flaw (CVE-2026-42167, CVSS 8.1) that can be triggered remotely—potentially even before authentication via logged fields like %U—allowing attackers to bypass authentication, create backdoor users, escalate privileges, and in PostgreSQL-backed deployments chain to remote code execution; affected versions up to 1.3.9 were fixed in 1.3.9a (released 2026-04-27), and administrators should urgently patch, review mod_sql usage and logging formats, or disable mod_sql-based logging until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
