logo

ProFTPD SQL Injection Flaw Opens Door To Remote Code Execution Attacks

ID: efb1d2f9-ae3b-5e11-9371-a3b7e165425d

STIX ID: report--efb1d2f9-ae3b-5e11-9371-a3b7e165425d

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Divya

...
...

ProFTPD's mod_sql module contains a serious SQL injection flaw (CVE-2026-42167, CVSS 8.1) that can be triggered remotely—potentially even before authentication via logged fields like %U—allowing attackers to bypass authentication, create backdoor users, escalate privileges, and in PostgreSQL-backed deployments chain to remote code execution; affected versions up to 1.3.9 were fixed in 1.3.9a (released 2026-04-27), and administrators should urgently patch, review mod_sql usage and logging formats, or disable mod_sql-based logging until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.